Generated remediation guidance and an executive summary. No account required.
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7.
Use CWE-770, Objectcomputing vendor hub and Micronaut product page to widen CVE-2026-33012 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-7611, CVE-2026-33013 and CVE-2021-32769 for nearby disclosures in the same product family.