PT-2026-1858 · Red Hat · Quarkus

Published

2026-01-07

·

Updated

2026-02-03

·

CVE-2025-66560

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Quarkus versions prior to 3.31.0 Quarkus versions prior to 3.27.2 Quarkus versions prior to 3.20.5
Description Quarkus is a Cloud Native framework for Java applications. A flaw exists in the HTTP layer related to response handling. When writing a response, the framework waits for previous response chunks to transmit fully. If the client connection drops during this wait, the worker thread remains blocked indefinitely. Repeated occurrences can exhaust worker threads, causing performance degradation or application unavailability. A health check monitoring worker thread pool status can detect abnormal thread retention.
Recommendations Update to Quarkus version 3.31.0 or later. Update to Quarkus version 3.27.2 or later. Update to Quarkus version 3.20.5 or later. Implement a health check to monitor the status and saturation of the worker thread pool.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-66560
GHSA-5RFX-CP42-P624

Affected Products

Quarkus