Visit NES for Micrometer Home Page

NES for Micrometer 1.15.x Release Notes

2 versions

Comprehensive release notes and changelog for NES for Micrometer 1.15.x, including security patches, bug fixes, and feature updates across all supported versions.

Oct 5, 2026
Latest: 1.15.14
3 Patched Vulnerabilities
VEX Statements

October 2026

Full Version:
1.15.12-micrometer-1.15.14

Security Fixes

This release patches the following:

  • MicrometerHttpClientInterceptor no longer retains request contexts indefinitely when asynchronous Apache HttpClient requests fail before receiving a response (medium severity, CVE-2026-59295). This line carries both the HttpClient 4 and HttpClient 5 interceptors, and the fix covers both.
  • Carriage-return and line-feed characters in metric names, tag keys and tag values are now sanitized in the Datadog and Etsy StatsD line builders and in LoggingMeterRegistry, preventing metric and log-line injection (medium severity, CVE-2026-59296).

September 2026

1.15.13

Released Sep 16, 2026
Full Version:
1.15.12-micrometer-1.15.13

Notes

First NES release of the 1.15.x line. It matches upstream 1.15.12 and carries no functional changes, so it is the baseline later patches build on.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.