Skip to content
Red HatCVE-2026-94449

Red Hat SmallRye Fault Tolerance: resource exhaustion

High7.5CVE-2026-94449 · Published Sep 21, 2026 · updated Sep 25, 2026

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Exploit Intelligence
Product
all versionsNo fix yet
Red Hat Fuse 7
Product
all versionsNo fix yet
Red Hat build of Apache Camel 4 for Quarkus 3
Product
all versionsNo fix yet
Red Hat build of Apicurio Registry 3
Product
all versionsNo fix yet
Red Hat build of Quarkus
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Red Hat advisories

All Red Hat
Advisory
Red Hat libstoragemgmt: buffer overflow
Medium5.5Sep 21
usbredir: out-of-bounds write
Medium4.1Sep 21
Red Hat fetchmail: stack buffer overflow
High8.1Sep 21
Red Hat pki-core: improper authorization
High8.1Sep 21
Red Hat OpenShift Container Platform 4: improper signature check
High7.4Sep 21
Red Hat Openshift Data Foundation 4: improper signature check
High7.1Sep 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.