Red HatCVE-2026-87742
Red Hat quarkus-websockets-next. This vulnerability: denial of service
High7.5CVE-2026-87742 · Published Sep 17, 2026 · updated Sep 22, 2026
A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space, leading to a java.lang.OutOfMemoryError that crashes the Java Virtual Machine (JVM).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Exploit Intelligence Product | all versions | No fix yet |
| Red Hat Enterprise Linux AI (RHEL AI) 3 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | Red Hat Keycloak.: capture-replay | High7.4 | 26.7.4 |
| Sep 17 | Red Hat libxml2: null pointer dereference | Medium5.5 | No fix yet |
| Sep 17 | Red Hat SmallRye JWT: path traversal | Medium5.3 | No fix yet |
| Sep 17 | Red Hat bmctest: missing authentication | Medium5.3 | No fix yet |
| Sep 17 | Red Hat Satellite 6: improper authorization | Medium4.3 | No fix yet |
| Sep 17 | Redis community: out-of-bounds read | High7.1 | No fix yet |