#VU122774 Missing Release of Resource after Effective Lifetime in Hibernate Reactive - CVE-2025-14969
Published: February 12, 2026
Hibernate Reactive
Hibernate Team
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a remote client can prematurely close the HTTP connection, when an HTTP endpoint is exposed to perform database operations. A remote user can leak connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.