Allocation of Resources Without Limits or Throttling in Quarkus - CVE-2026-87742
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service by exhausting heap memory and crashing the JVM.
The vulnerability exists due to allocation of resources without limits or throttling in the quarkus-websockets-next WebSocket endpoint's inbound MPSC queue when processing inbound WebSocket messages. A remote attacker can stream messages over a single connection faster than the application's handler can process them to cause a denial of service by exhausting heap memory and crashing the JVM.