Missing Release of Resource after Effective Lifetime in Hibernate Reactive - CVE-2025-14969
Published: February 12, 2026
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a remote client can prematurely close the HTTP connection, when an HTTP endpoint is exposed to perform database operations. A remote user can leak connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
Affected software
Enterprise Build of Quarkus
How to mitigate CVE-2025-14969
Enterprise Build of Quarkus - update to 3.27.2