CVE Explorer
CVE-2026-44241
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header. Because Locale.forLanguageTag() accepts arbitrary BCP 47 private-use extensions (
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"micronaut-core","vendor":"micronaut-projects","versions":[{"status":"affected","version":">= 4.3.0, < 4.10.22"},{"status":"affected","version":">= 3.10.0, < 3.10.6"},{"status":"affected","version":"< 3.8.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/problemTypes/0/descriptions/0
Source references
8 source assertions{"name":"https://github.com/micronaut-projects/micronaut-core/commit/48f05ae8dc4157816fe0050c5cf730be7d44f8b3","tags":["x_refsource_MISC"],"url":"https://github.com/micronaut-projects/micronaut-core/commit/48f05ae8dc4157816fe0050c5cf730be7d44f8b3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/1
{"name":"https://github.com/micronaut-projects/micronaut-core/commit/c2048ab740c2efdfe227813f203176e0ef93f892","tags":["x_refsource_MISC"],"url":"https://github.com/micronaut-projects/micronaut-core/commit/c2048ab740c2efdfe227813f203176e0ef93f892"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/2
{"name":"https://github.com/micronaut-projects/micronaut-core/commit/c6ca8782de7338732e887d090f38c9e941bcb284","tags":["x_refsource_MISC"],"url":"https://github.com/micronaut-projects/micronaut-core/commit/c6ca8782de7338732e887d090f38c9e941bcb284"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/3
{"name":"https://github.com/micronaut-projects/micronaut-core/releases/tag/v3.10.6","tags":["x_refsource_MISC"],"url":"https://github.com/micronaut-projects/micronaut-core/releases/tag/v3.10.6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/4
{"name":"https://github.com/micronaut-projects/micronaut-core/releases/tag/v3.8.14","tags":["x_refsource_MISC"],"url":"https://github.com/micronaut-projects/micronaut-core/releases/tag/v3.8.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/5
{"name":"https://github.com/micronaut-projects/micronaut-core/releases/tag/v4.10.22","tags":["x_refsource_MISC"],"url":"https://github.com/micronaut-projects/micronaut-core/releases/tag/v4.10.22"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/6
{"tags":["exploit"],"url":"https://github.com/micronaut-projects/micronaut-core/security/advisories/GHSA-8hjv-92q9-g4xj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/adp/0/references/0
{"name":"https://github.com/micronaut-projects/micronaut-core/security/advisories/GHSA-8hjv-92q9-g4xj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/micronaut-projects/micronaut-core/security/advisories/GHSA-8hjv-92q9-g4xj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aea4524332aa2fafc105c3bea51f76fc3d2a961d6828504531ecd4d8acfd5373 · sha256:f78f9a3ba7465003… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.