Impact
The vulnerability in quarkus-websockets-next allows a remote attacker to stream frames over a WebSocket connection faster than the application can process them. Because the library uses unbounded message buffering and does not implement read backpressure, the accumulated data quickly exhausts Java heap space, leading to a java.lang.OutOfMemoryError that crashes the JVM. This results in a denial of service for the affected application. The weakness is a classic example of uncontrolled resource consumption, mapped to CWE‑770.
Affected Systems
Affected vendors are Red Hat (Red Hat build of Quarkus) and Red Hat Enterprise Linux AI (RHEL AI) 3. The products impacted include the Red Hat build of Quarkus (version 3) and RHEL AI 3. These systems run the affected quarkus‑websockets‑next component and are listed in the known CPEs for Quarkus 3 and RHEL AI 3. No other vendor or product versions are explicitly identified in the CNA data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. EPSS is not available, and the issue is not listed in the CISA KEV catalog, implying no widely known exploits yet. The likely attack vector is a remote WebSocket endpoint that the attacker can flood with large or numerous messages. Because no official patch or ongoing workaround is provided by Red Hat, the risk is primarily mitigated by network controls, configuration hardening, and runtime monitoring.
OpenCVE Enrichment