Smallrye-fault-tolerance: smallrye fault tolerance
Published Mar 12, 2025
7.5
HIGHCVSS 3.1
EPSS 1.00%
Description
A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Integration Camel K 1 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
| |||
| Red Hat | Red Hat build of Apicurio Registry 2 | affected |
|
No data.
No data.
Red Hat Build of Apache Camel 4.8 for Quarkus 3.15
quarkus-camel-bom
Fixed · RHSA-2025:3541
Red Hat Build of Apache Camel 4.8 for Quarkus 3.15
quarkus-cxf-bom
Fixed · RHSA-2025:3541
Red Hat build of Apache Camel 4.8.5 for Spring Boot
smallrye-fault-tolerance-core
Fixed · RHSA-2025:3543
Red Hat build of Quarkus 3.15.4
smallrye-fault-tolerance-core
Fixed · RHSA-2025:3376
Red Hat Fuse 7
smallrye-fault-tolerance-core
Out of support scope
Red Hat Integration Camel K 1
smallrye-fault-tolerance-core
Will not fix
Red Hat JBoss Enterprise Application Platform 7
smallrye-fault-tolerance-core
Will not fix
Red Hat JBoss Enterprise Application Platform 8
smallrye-fault-tolerance-core
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
smallrye-fault-tolerance-core
Not affected
Red Hat build of Apicurio Registry 2
smallrye-fault-tolerance-core
Affected
Red Hat build of Apicurio Registry 3
smallrye-fault-tolerance-core
Not affected
Red Hat build of Quarkus
smallrye-fault-tolerance-apiimpl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 | quarkus-camel-bom | Fixed | RHSA-2025:3541 |
| Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 | quarkus-cxf-bom | Fixed | RHSA-2025:3541 |
| Red Hat build of Apache Camel 4.8.5 for Spring Boot | smallrye-fault-tolerance-core | Fixed | RHSA-2025:3543 |
| Red Hat build of Quarkus 3.15.4 | smallrye-fault-tolerance-core | Fixed | RHSA-2025:3376 |
| Red Hat Fuse 7 | smallrye-fault-tolerance-core | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | smallrye-fault-tolerance-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | smallrye-fault-tolerance-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | smallrye-fault-tolerance-core | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | smallrye-fault-tolerance-core | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | smallrye-fault-tolerance-core | Affected | n/a |
| Red Hat build of Apicurio Registry 3 | smallrye-fault-tolerance-core | Not affected | n/a |
| Red Hat build of Quarkus | smallrye-fault-tolerance-apiimpl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Red Hat statement
This vulnerability allows a remote attacker to cause an out-of-memory issue when calling the metrics URI, resulting in a denial of service. As this flaw can be triggered via the network, it has been rated with an important severity.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (12)
- https://access.redhat.com/errata/RHSA-2025:3376 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:3541 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:3543 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-2240 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2351452 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-gfh6-3pqw-x2j4 Advisory
- https://github.com/smallrye/smallrye-fault-tolerance/commit/e8bcad3d5e8bbac0a3219bd5c13661adf6ed6bbb
- https://github.com/smallrye/smallrye-fault-tolerance/pull/985
- https://github.com/smallrye/smallrye-fault-tolerance/pull/985/files#diff-88c4a089e0cb88e4bdf285490e2617c29b9979a778e33957e4448260e286b91aR299
- https://nvd.nist.gov/vuln/detail/CVE-2025-2240
- https://smallrye.io/blog/fault-tolerance-6-9-0
- https://www.cve.org/CVERecord?id=CVE-2025-2240
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:3376 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:3541 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:3543 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2025-2240 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2351452 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-gfh6-3pqw-x2j4 | Advisory | |
| https://github.com/smallrye/smallrye-fault-tolerance/commit/e8bcad3d5e8bbac0a3219bd5c13661adf6ed6bbb | ||
| https://github.com/smallrye/smallrye-fault-tolerance/pull/985 | ||
| https://github.com/smallrye/smallrye-fault-tolerance/pull/985/files#diff-88c4a089e0cb88e4bdf285490e2617c29b9979a778e33957e4448260e286b91aR299 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-2240 | ||
| https://smallrye.io/blog/fault-tolerance-6-9-0 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-2240 |
Change history (0)
No recorded changes yet.