CVE-2025-2240

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.
Configurations

No configuration.

History

02 Apr 2025, 17:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3541 -

02 Apr 2025, 14:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:3376 -

13 Mar 2025, 20:15

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Smallrye, donde smallrye-fault-tolerance es vulnerable a un problema de falta de memoria (OOM). Esta vulnerabilidad se activa externamente al llamar a la URI de métricas. Cada llamada crea un nuevo objeto dentro de meterMap y puede provocar una denegación de servicio (DoS).
References
  • () https://github.com/advisories/GHSA-gfh6-3pqw-x2j4 -

12 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 15:15

Updated : 2025-04-02 17:15


NVD link : CVE-2025-2240

Mitre link : CVE-2025-2240

CVE.ORG link : CVE-2025-2240


JSON object : View

Products Affected

No product.

CWE
CWE-1325

Improperly Controlled Sequential Memory Allocation