{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/quarkus-quarkus-websockets-next/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:quarkus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87742"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quarkus (quarkus-websockets-next)","Quarkus"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","java","application-security","web-application","security-flaw","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability exists in the quarkus-websockets-next component of the Red Hat Quarkus framework, identified as CVE-2026-87742. This issue stems from the lack of read backpressure and the implementation of unbounded message buffering within the WebSocket handling logic. A remote, unauthenticated attacker can exploit this flaw by flooding a single WebSocket connection with high-frequency messages. Because the application fails to regulate the data ingress rate, the incoming messages accumulate in the system's memory heap. This rapid, uncontrolled allocation of memory leads to a java.lang.OutOfMemoryError, ultimately forcing the JVM to crash and resulting in a complete Denial of Service for the affected service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate unavailability of the application due to a JVM crash. This Denial of Service vulnerability impacts any service utilizing the vulnerable quarkus-websockets-next extension. Depending on the service architecture, this may lead to significant operational disruption for organizations relying on the affected Quarkus-based applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all applications currently utilizing the quarkus-websockets-next extension within the environment.\u003c/li\u003e\n\u003cli\u003eMonitor application logs and system resource telemetry for sudden, high-frequency WebSocket traffic volume and recurring JVM heap usage spikes.\u003c/li\u003e\n\u003cli\u003eConsult Red Hat security advisories for the specific patched version of Quarkus and prioritize applying updates to all vulnerable nodes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T12:05:16Z","date_published":"2026-09-17T15:59:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-quarkus-websockets-dos/","summary":"A vulnerability in quarkus-websockets-next allows a remote attacker to cause a Denial of Service via heap exhaustion by streaming WebSocket messages faster than the application can process them.","title":"Denial of Service Vulnerability in Quarkus WebSockets Next","url":"https://feed.craftedsignal.io/briefs/2026-09-quarkus-websockets-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Quarkus (Quarkus-Websockets-Next)","version":"https://jsonfeed.org/version/1.1"}