The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningThere is no fixed version for org.springframework.cloud:spring-cloud-sleuth-instrumentation.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the Spring TX (transaction) instrumentation classes in this package. A remote user can issue calls that drive the transaction instrumentation to allocate resources without limits or throttling, resulting in a denial-of-service (DoS) condition.
Note:
Spring Cloud Sleuth is end-of-life and has been superseded by Micrometer Tracing; the open source repository was archived on May 28, 2026, and no public fix commit exists. The fixed version 3.1.14 is available under Spring Enterprise Support only and is not published to Maven Central, where open source releases end at 3.1.11.
This can be mitigated by disabling Spring TX instrumentation, for example by setting spring.sleuth.tx.enabled=false.