Bug 2530522 (CVE-2026-87742) - CVE-2026-87742 quarkus-websockets-next: Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering
Summary: CVE-2026-87742 quarkus-websockets-next: Denial of Service (OOM) in quarkus-we...
Keywords:
Status: NEW
Alias: CVE-2026-87742
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-09 06:08 UTC by OSIDB Bzimport
Modified: 2026-09-17 13:23 UTC (History)
57 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-09 06:08:27 UTC
Title: Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering
Summary: 

A Denial of Service vulnerability exists in the quarkus-websockets-next extension due to unbounded message buffering.The framework uses an unbounded queue and fails to apply read backpressure on the underlying network socket. An attacker can stream messages over a single connection faster than the application's handler can process them. This rapidly exhausts heap space, causing a java.lang.OutOfMemoryError that crashes the JVM.

Component: io.quarkus:quarkus-vertx-httpCWE: CWE-400, CWE-770
Scoring:  CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5/10)
Affected versions: 3.27, 3.33

Credit: Michael Read (https://github.com/Michael-JRead)


Note You need to log in before you can comment on or make changes to this bug.