Skip to content

fix(deps): update dependency io.micrometer:micrometer-core to v1.15.12 [security] - #995

Open
renovate[bot] wants to merge 1 commit into
scylla-4.xfrom
renovate/maven-io.micrometer-micrometer-core-vulnerability
Open

fix(deps): update dependency io.micrometer:micrometer-core to v1.15.12 [security]#995
renovate[bot] wants to merge 1 commit into
scylla-4.xfrom
renovate/maven-io.micrometer-micrometer-core-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 8, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
io.micrometer:micrometer-core 1.15.41.15.12 age confidence

Micrometer gRPC server instrumentation DoS

CVE-2026-40983 / GHSA-w737-wx49-qj23

More information

Details

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.

Affected versions:
Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

micrometer-metrics/micrometer (io.micrometer:micrometer-core)

v1.15.12: 1.15.12

Compare Source

🐞 Bug Fixes
  • ArrayIndexOutOfBoundsException when using LongTaskTimer #​3877
  • Jetty 12's TimedHandler marks some requests with outcome UNKNOWN #​7276
  • MeterRegistry closes HighCardinalityTagsDetector twice if the registry is closed twice #​7409
  • Reduce allocation in HTTP server instrumentation #​7580
  • Reduce allocation in gRPC server convention #​7581
📔 Documentation
  • Clarify time series produced by LongTaskTimer when using Prometheus #​6507
  • Document metrics that need to close the MeterBinder #​4624
  • Multigauge Documentation lacks overwrite=true #​4403
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​izeye, @​jewoodev, @​codingkiddo, @​schiemon, @​blaspat

v1.15.11: 1.15.11

Compare Source

🐞 Bug Fixes
  • Invalid reflection hint in micrometer-core for native GraalVM 25 build #​7316
🔨 Dependency Upgrades
  • Bump org.apache.maven:maven-resolver-provider from 3.9.13 to 3.9.14 #​7280
  • Bump spring6 from 6.2.16 to 6.2.17 #​7294
❤️ Contributors

@​Joowon-Seo and @​ribafish
Thank you to all the contributors who worked on this release:

v1.15.10: 1.15.10

Compare Source

📔 Documentation
  • Document (Default)MeterObservationHandler #​6361
  • Document statsd UDS config #​5730
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​seonghyeoklee, @​kangdaeun1022, and @​izeye

v1.15.9: 1.15.9

Compare Source

🐞 Bug Fixes
  • Add immutable noop Observation.Context #​7133
  • OSGi test isn't reporting failures #​7060
📔 Documentation
  • Docs: Align AsciiDoc callout syntax #​7148
  • Improve documentation of ExecutorServiceMetrics #​7083
🔨 Dependency Upgrades
  • Bump dropwizard-metrics from 4.2.37 to 4.2.38 #​7120
  • Bump gradle-wrapper from 8.14.3 to 8.14.4 #​7112
  • Bump io.spring.develocity.conventions from 0.0.24 to 0.0.25 #​7099
  • Bump org.assertj:assertj-core from 3.27.6 to 3.27.7 #​7123
❤️ Contributors

@​izeye, @​mateusz-nalepa, and @​tkmsaaaam
Thank you to all the contributors who worked on this release:

v1.15.8: 1.15.8

Compare Source

🐞 Bug Fixes
  • ExecutorServiceMetrics: repeatedly logs exception when monitoring ThreadPerTaskExecutor without --add-opens #​6726
🔨 Dependency Upgrades
  • Bump maven-resolver from 1.9.24 to 1.9.25 #​6965
  • Bump spring6 from 6.2.14 to 6.2.15 #​6969
  • Bump testcontainers from 1.21.3 to 1.21.4 #​6993
❤️ Contributors

Thank you to all the contributors who worked on this release:
@​izeye

v1.15.7: 1.15.7

Compare Source

🐞 Bug Fixes
  • Don't filter log events in LogbackMetricsBenchmark #​6891
📔 Documentation
  • Add link to the latest Micrometer Team talk #​6881
  • Make cross-references more consistent in the docs #​6915
🔨 Dependency Upgrades
  • Bump spring6 from 6.2.12 to 6.2.14 #​6911
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​MiLabuda, and @​ngocnhan-tran1996

v1.15.6: 1.15.6

Compare Source

🐞 Bug Fixes
  • Exclude java.* from OSGI Import-Package #​6810
📔 Documentation
  • Add a note about client-side percentiles with histogram #​6836
  • Add docs for HighCardinalityTagsDetector #​6822

v1.15.5: 1.15.5

🐞 Bug Fixes
  • Close scope in same thread in ObservedAspect #​6727
  • Synchronize access of current connections in JettyConnectionMetrics #​6578
🔨 Dependency Upgrades
  • Bump dropwizard-metrics from 4.2.36 to 4.2.37 #​6733
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​deadok22 and @​pema4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Aug 8, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Pro Plus

Run ID: 2535a1f1-ec3c-4164-b893-2d85486d74ff

📥 Commits

Reviewing files that changed from the base of the PR and between 1bb0a6d and 950d92e.

📒 Files selected for processing (1)
  • pom.xml

📝 Walkthrough

Walkthrough

The pull request updates the managed io.micrometer:micrometer-core dependency in pom.xml from version 1.15.4 to 1.15.12.

Possibly related PRs

Suggested labels: dependencies, java

Suggested reviewers: scylladb-promoter, dkropachev, nikagra

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the Micrometer dependency update and its security purpose.
Description check ✅ Passed The description explains the dependency update, security vulnerability, affected versions, and included release changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants