Visit NES for Micrometer Home Page
NES for Micrometer 1.9.x Release Notes
1 version
Comprehensive release notes and changelog for NES for Micrometer 1.9.x, including security patches, bug fixes, and feature updates across all supported versions.
September 2026
1.9.19
Released Sep 17, 2026 Full Version:
1.9.17-micrometer-1.9.19
Security Fixes
This release patches the following:
- Non-standard request methods can no longer create unbounded
methodtag values inHttpRequestTagsandJerseyTags(high severity, CVE-2026-40984). MicrometerHttpClientInterceptorno longer retains request contexts indefinitely when asynchronous Apache HttpClient requests fail before receiving a response (medium severity, CVE-2026-59295).- Carriage-return and line-feed characters in metric names, tag keys and tag values are now sanitized in the Datadog and Etsy StatsD line builders and in
LoggingMeterRegistry, preventing metric and log-line injection (medium severity, CVE-2026-59296).
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh