Executive brief
The Micronaut HTTP Client, a tool used by developers to make web requests in Java applications, fails to limit the number of times it follows web redirects. An attacker could exploit this by providing a malicious URL that causes the application to enter an infinite loop, potentially crashing the service or making it unavailable to legitimate users. This issue affects applications using Micronaut versions 3, 4, and 5.
Technical details
The Micronaut HTTP Client (Netty-based) lacks a default or configurable maximum redirect limit. This vulnerability allows a remote attacker to trigger an infinite redirection loop by directing the client to a malicious endpoint that continuously redirects to itself or another participating URL. This results in resource exhaustion and a Denial of Service (DoS) condition. The issue is present in Micronaut versions prior to 3.10.7, 4.10.24, and 5.0.1. Patches have been released for all affected major versions to implement redirection limits.
Affected products
- Micronaut Foundation Micronaut HTTP Client < 3.10.7, >= 4.0.0-M1, < 4.10.24, >= 5.0.0-M1, < 5.0.1
Timeline
- 2026-06-01: disclosed: Initial publication to micronaut-projects/micronaut-core
- 2026-07-09: advisory: GitHub Advisory published