Back

HIGH

Smallrye-fault-tolerance: smallrye fault tolerance

Published Mar 12, 2025

Description

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

Affected products

Remediation

Vendor solution

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Red Hat statement

This vulnerability allows a remote attacker to cause an out-of-memory issue when calling the metrics URI, resulting in a denial of service. As this flaw can be triggered via the network, it has been rated with an important severity.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 12, 2025
Updated Aug 13, 2026
Reserved Mar 12, 2025
CISA Vulnrichment
Updated Mar 12, 2025
NVD
Status Deferred
Modified Aug 13, 2026
Red Hat
Severity Important
Public date Mar 12, 2025
GHSA-GFH6-3PQW-X2J4