Description
Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.
Published: 2026-10-11
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an uninitialized memory issue in the chat‑scopes WebSocket /_chat/routes endpoint. Unauthenticated remote clients can repeatedly send CONNECT frames reusing a single chatId, causing orphaned scopes to accumulate in activeScopes until the JVM exits. This results in uncontrolled memory consumption and a denial of service. The weakness is classified as an improper memory management flaw (CWE‑401).

Affected Systems

The flaw affects deployments of Quarkus LangChain4j versions 1.9.0 through 1.14.1, which are used to add AI chat functionality in Quarkus applications. Any system using these versions with the chat‑scopes WebSocket enabled is at risk.

Risk and Exploitability

The CVSS score is 6.9, indicating moderate severity. The EPSS score is not available, and the vulnerability has not been listed in CISA’s KEV catalog. Attackers need no authentication and can exploit the flaw by opening repetitive WebSocket connections to the /_chat/routes endpoint, which will progressively deplete server memory. The impact is a service interruption that can lead to JVM crashes or unresponsive applications.

Generated by OpenCVE AI on October 11, 2026 at 13:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version of Quarkus LangChain4j that includes a fix for the chat‑scopes memory leak (any release newer than 1.14.1 if available).
  • If an upgrade is not immediately possible, disable or remove the /_chat/routes WebSocket endpoint to block exploitation.
  • Implement a rate limiter or connection limit on the WebSocket service to prevent repeated CONNECT frames from exhausting memory until a patch is applied.

Generated by OpenCVE AI on October 11, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.
Title Quarkus LangChain4j 1.9.0 through 1.14.1 Memory Exhaustion via /_chat/routes WebSocket
Weaknesses CWE-401
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:49.295Z

Reserved: 2026-10-11T01:53:24.418Z

Link: CVE-2026-108748

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:19.523

Modified: 2026-10-11T13:17:19.523

Link: CVE-2026-108748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime