<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Micronaut Framework</title>
  <link>https://cvedaily.com/pages/tags/micronaut.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/micronaut.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Micronaut Framework</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-44242 – Micronaut Framework is a JVM-based full stack Java framework designed for buildi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44242</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44242</strong></p>
  <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Prior to 4.10.22, the bundleCache is keyed by (Locale, baseName) where the locale originates from the HTTP Accept-Language header. In applications that explicitly register a ResourceBundleMessageSource bean and serve HTML error responses, an unauthenticated attacker can ex…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44241 – Micronaut Framework is a JVM-based full stack Java framework designed for buildi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44241</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44241</strong></p>
  <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33013 – Micronaut Framework is a JVM-based full stack Java framework designed for buildi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33013</guid>
    <pubDate>Fri, 20 Mar 2026 05:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33013</strong></p>
  <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33012 – Micronaut Framework is a JVM-based full stack Java framework designed for buildi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33012</guid>
    <pubDate>Fri, 20 Mar 2026 05:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33012</strong></p>
  <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications.  Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23639 – Micronaut Framework is a modern, JVM-based, full stack Java framework designed f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23639</guid>
    <pubDate>Fri, 09 Feb 2024 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23639</strong></p>
  <p>Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks. While not typical of a production application, these attacks may have more impact on a development environment where suc…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36820 – Micronaut Security is a security solution for applications. Prior to versions 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36820</guid>
    <pubDate>Mon, 09 Oct 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36820</strong></p>
  <p>Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC setup using Micronaut where multiple OIDC applications exists for the same issuer but token auth are not meant to be shared.…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21700 – Micronaut is a JVM-based, full stack Java framework designed for building JVM we...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21700</guid>
    <pubDate>Tue, 18 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21700</strong></p>
  <p>Micronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Kotlin and the Groovy language. In affected versions sending an invalid Content Type header leads to memory leak in DefaultArgumentConversionContext as this type is erroneously used in static state. ### Impact Sending an invalid Content Type header leads to memory leak in `Default…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32769 – Micronaut is a JVM-based, full stack Java framework designed for building JVM ap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32769</guid>
    <pubDate>Fri, 16 Jul 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32769</strong></p>
  <p>Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7611 – All versions of io.micronaut:micronaut-http-client before 1.2.11 and all version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7611</guid>
    <pubDate>Mon, 30 Mar 2020 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7611</strong></p>
  <p>All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7611">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
