Description
A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space, leading to a java.lang.OutOfMemoryError that crashes the Java Virtual Machine (JVM).
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

The vulnerability in quarkus-websockets-next allows a remote attacker to stream frames over a WebSocket connection faster than the application can process them. Because the library uses unbounded message buffering and does not implement read backpressure, the accumulated data quickly exhausts Java heap space, leading to a java.lang.OutOfMemoryError that crashes the JVM. This results in a denial of service for the affected application. The weakness is a classic example of uncontrolled resource consumption, mapped to CWE‑770.

Affected Systems

Affected vendors are Red Hat (Red Hat build of Quarkus) and Red Hat Enterprise Linux AI (RHEL AI) 3. The products impacted include the Red Hat build of Quarkus (version 3) and RHEL AI 3. These systems run the affected quarkus‑websockets‑next component and are listed in the known CPEs for Quarkus 3 and RHEL AI 3. No other vendor or product versions are explicitly identified in the CNA data.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability. EPSS is not available, and the issue is not listed in the CISA KEV catalog, implying no widely known exploits yet. The likely attack vector is a remote WebSocket endpoint that the attacker can flood with large or numerous messages. Because no official patch or ongoing workaround is provided by Red Hat, the risk is primarily mitigated by network controls, configuration hardening, and runtime monitoring.

Generated by OpenCVE AI on September 17, 2026 at 21:40 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Check Red Hat for any available update or patch for the Quarkus library and apply it as soon as it is released.
  • Deploy a reverse proxy or network gateway that limits the rate and size of WebSocket traffic to prevent flooding attacks.
  • Configure the Quarkus application to enforce a maximum WebSocket message size or enable backpressure handling if supported by the framework.
  • Continuously monitor JVM heap usage and set alerts or auto‑restart policies to recover from OutOfMemoryError events.

Generated by OpenCVE AI on September 17, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3
Vendors & Products Redhat quarkus
References

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Quarkus
Vendors & Products Redhat build Of Quarkus

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space, leading to a java.lang.OutOfMemoryError that crashes the Java Virtual Machine (JVM).
Title Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded message buffering
First Time appeared Redhat
Redhat enterprise Linux Ai
Redhat exploit Intelligence
Redhat quarkus
Weaknesses CWE-770
CPEs cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:exploit_intelligence:0
cpe:/a:redhat:quarkus:3
Vendors & Products Redhat
Redhat enterprise Linux Ai
Redhat exploit Intelligence
Redhat quarkus
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Build Of Quarkus Enterprise Linux Ai Exploit Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T15:39:08.296Z

Reserved: 2026-09-09T05:58:00.263Z

Link: CVE-2026-87742

cve-icon Vulnrichment

Updated: 2026-09-17T15:19:14.295Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T15:16:56.137

Modified: 2026-09-22T16:18:06.833

Link: CVE-2026-87742

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T13:10:22Z

Links: CVE-2026-87742 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:00Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling