Impact
The vulnerability is an uninitialized memory issue in the chat‑scopes WebSocket /_chat/routes endpoint. Unauthenticated remote clients can repeatedly send CONNECT frames reusing a single chatId, causing orphaned scopes to accumulate in activeScopes until the JVM exits. This results in uncontrolled memory consumption and a denial of service. The weakness is classified as an improper memory management flaw (CWE‑401).
Affected Systems
The flaw affects deployments of Quarkus LangChain4j versions 1.9.0 through 1.14.1, which are used to add AI chat functionality in Quarkus applications. Any system using these versions with the chat‑scopes WebSocket enabled is at risk.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. The EPSS score is not available, and the vulnerability has not been listed in CISA’s KEV catalog. Attackers need no authentication and can exploit the flaw by opening repetitive WebSocket connections to the /_chat/routes endpoint, which will progressively deplete server memory. The impact is a service interruption that can lead to JVM crashes or unresponsive applications.
OpenCVE Enrichment