A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections. |
| Title | io.quarkus/quarkus-hibernate-reactive-panache: Hibernate Reactive: Denial of Service due to connection leak on HTTP client disconnect | Hibernate-reactive-core: hibernate reactive: denial of service due to connection leak on http client disconnect |
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat openshift Devspaces Redhat quarkus |
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:openshift_devspaces:3 cpe:/a:redhat:quarkus:3 |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat openshift Devspaces Redhat quarkus |
|
| References |
|
Sat, 20 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | io.quarkus/quarkus-hibernate-reactive-panache: Hibernate Reactive: Denial of Service due to connection leak on HTTP client disconnect | |
| Weaknesses | CWE-772 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-01-26T19:36:40.424Z
Updated: 2026-01-26T21:00:10.284Z
Reserved: 2025-12-19T10:54:33.492Z
Link: CVE-2025-14969
Updated: 2026-01-26T21:00:07.000Z
Status : Received
Published: 2026-01-26T20:16:08.313
Modified: 2026-01-26T20:16:08.313
Link: CVE-2025-14969