Description
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.4.SP2 and 3.33.1 through 3.33.2.SP2 contain a flaw in Quarkus REST that allows a malicious caller to trigger a denial of service by sending multipart MIME requests with unbounded accumulation of part‑header bytes. The vulnerability can cause excessive memory or resource consumption, leading the application to become unresponsive or to crash. This issue is classified under CWE‑770 and carries a CVSS score of 7.5, indicating a high‑severity potential impact on availability for affected deployments.

Affected Systems

IBM Enterprise Build of Quarkus, specifically the 3.27.x line up to 3.27.4.SP2 and the 3.33.x line up to 3.33.2.SP2. Systems running any of these versions without the fix are vulnerable.

Risk and Exploitability

The flaw can be exploited remotely by any user who can access the exposed Quarkus REST endpoints. The EPSS score is 0.00549, indicating a very low but non‑zero probability of exploitation; the high CVSS score highlights the substantial risk. The vulnerability is not listed in the CISA KEV catalog, but the lack of real‑time exploitation data does not reduce the importance of applying the fix promptly. Attackers can send crafted multipart MIME payloads to exhaust server resources and force a service interruption without requiring elevated privileges.

Generated by OpenCVE AI on August 2, 2026 at 05:21 UTC.

Remediation

Vendor Solution

The issues are addressed in IBM Enterprise Build of Quarkus 3.27.4.SP3 and 3.33.2.SP3. To update your project to IBM Enterprise Build of Quarkus 3.27.4.SP3 or 3.33.2.SP3, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .


OpenCVE Recommended Actions

  • Update the IBM Enterprise Build of Quarkus to version 3.27.4.SP3 or 3.33.2.SP3 following IBM’s upgrade instructions.
  • If an immediate upgrade is infeasible, configure request filtering or a reverse‑proxy rule to limit multipart MIME part‑header size, preventing unbounded accumulation and mitigating resource exhaustion.
  • Implement monitoring and alerting for abnormal memory consumption or service restarts, and ensure that logs capture multipart request sizes for forensic analysis.

Generated by OpenCVE AI on August 2, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus REST. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted multipart/form-data request with an excessively large header section. This unbounded accumulation of MIME part-header bytes can exhaust the Java Virtual Machine (JVM) heap memory, leading to an OutOfMemoryError. The primary consequence is a denial of service, causing the application to crash. IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
Title io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
First Time appeared Ibm
Ibm enterprise Build Of Quarkus
CPEs cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.4.sp2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.4.sp2:sp2:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.2.sp2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.2.sp2:sp2:*:*:*:*:*:*
Vendors & Products Ibm
Ibm enterprise Build Of Quarkus
References

Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus REST. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted multipart/form-data request with an excessively large header section. This unbounded accumulation of MIME part-header bytes can exhaust the Java Virtual Machine (JVM) heap memory, leading to an OutOfMemoryError. The primary consequence is a denial of service, causing the application to crash.
Title io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service
First Time appeared Redhat
Redhat quarkus
Weaknesses CWE-770
CPEs cpe:/a:redhat:quarkus:3.27::el8
Vendors & Products Redhat
Redhat quarkus
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Subscriptions

Ibm Enterprise Build Of Quarkus
Redhat Quarkus
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T16:20:01.475Z

Reserved: 2026-07-20T14:31:00.798Z

Link: CVE-2026-16308

cve-icon Vulnrichment

Updated: 2026-07-30T16:19:56.091Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T15:16:26.910

Modified: 2026-07-30T17:16:28.837

Link: CVE-2026-16308

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-29T13:19:42Z

Links: CVE-2026-16308 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling