CVE-2023-34053
published 2023-11-28CVE-2023-34053: In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS)…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.15%
63.4th percentile
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| spring | spring_framework | >= 6.0.0 < 6.0.14 | 6.0.14 |
| vmware | spring_framework | >= 6.0.0 < 6.0.14 | 6.0.14 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_oracle7.5MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Foundation (Spring Framework) — CVE-2023-34053
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2023-34053 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Foundation (Spring Framework) — CVE-2023-34053
Oracle Oracle Retail Applications Risk Matrix: Foundation (Spring Framework) vulnerability
CVE: CVE-2023-34053
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Spring Framework) — CVE-2023-34053
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-34053 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (Spring Framework) — CVE-2023-34053
Oracle Oracle Communications Applications Risk Matrix: Security (Spring Framework) vulnerability
CVE: CVE-2023-34053
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Spring Framework) — CVE-2023-34053
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2023-34053 [MEDIUM] Oracle Oracle Communications Risk Matrix: Third Party (Spring Framework) — CVE-2023-34053
Oracle Oracle Communications Risk Matrix: Third Party (Spring Framework) vulnerability
CVE: CVE-2023-34053
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
springframework: io.micrometer: micrometer-core classpath vulnerable to denial of service
vendor_redhat·2023-11-27·CVSS 5.3
CVE-2023-34053 [MEDIUM] CWE-400 springframework: io.micrometer: micrometer-core classpath vulnerable to denial of service
springframework: io.micrometer: micrometer-core classpath vulnerable to denial of service
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC or Spring WebFlux
* io.micrometer:micrometer-core is on the classpath
* an ObservationRegistry is configured in the application to record observations
Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.
Statement: Red Hat Products are not affected by this vulnerability.
Mitigation: As a temporary workaround, Spring Boot 3.0.x and 3.1.x users can choose
Debian
CVE-2023-34053: libspring-java - In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provid...
vendor_debian·2023·CVSS 5.3
CVE-2023-34053 [MEDIUM] CVE-2023-34053: libspring-java - In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provid...
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Spring Framework vulnerable to denial of service
osv·2023-11-28
CVE-2023-34053 [HIGH] Spring Framework vulnerable to denial of service
Spring Framework vulnerable to denial of service
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC or Spring WebFlux
* io.micrometer:micrometer-core is on the classpath
* an ObservationRegistry is configured in the application to record observations
Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.
OSV
CVE-2023-34053: In Spring Framework versions 6
osv·2023-11-28·CVSS 7.5
CVE-2023-34053 [HIGH] CVE-2023-34053: In Spring Framework versions 6
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an ObservationRegistry is configured in the application to record observations Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.
GHSA
Spring Framework vulnerable to denial of service
ghsa·2023-11-28
CVE-2023-34053 [HIGH] Spring Framework vulnerable to denial of service
Spring Framework vulnerable to denial of service
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC or Spring WebFlux
* io.micrometer:micrometer-core is on the classpath
* an ObservationRegistry is configured in the application to record observations
Typically, Spring Boot applications need the org.springframework.boot:spring-boot-actuator dependency to meet all conditions.
No detection rules found.
No public exploits indexed.
2023-11-28
Published