
We found results for “”
CVE-2025-1634
Good to know:


Date: February 26, 2025
A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.
Severity Score
Related Resources (17)
Severity Score
Weakness Type (CWE)
Missing Release of Memory after Effective Lifetime
CWE-401Top Fix

Upgrade Version
Upgrade to version io.quarkus:quarkus-resteasy:3.19.1;io.quarkus:quarkus-resteasy:3.15.3.1;io.quarkus:quarkus-resteasy:3.8.6.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |