Description

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

INFO

Published Date :

2025-03-12T14:55:15.889Z

Last Modified :

2025-11-24T09:19:31.181Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2240 vulnerability.

Vendors Products
Redhat
  • Apache Camel Spring Boot
  • Apicurio Registry
  • Camel Quarkus
  • Integration
  • Jboss Enterprise Application Platform
  • Jboss Fuse
  • Jbosseapxp
  • Quarkus
  • Service Registry

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact