Red HatCVE-2026-94449
Red Hat SmallRye Fault Tolerance: resource exhaustion
High7.5CVE-2026-94449 · Published Sep 21, 2026 · updated Sep 25, 2026
A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Exploit Intelligence Product | all versions | No fix yet |
| Red Hat Fuse 7 Product | all versions | No fix yet |
| Red Hat build of Apache Camel 4 for Quarkus 3 Product | all versions | No fix yet |
| Red Hat build of Apicurio Registry 3 Product | all versions | No fix yet |
| Red Hat build of Quarkus Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-400
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 21 | Red Hat libstoragemgmt: buffer overflow | Medium5.5 | No fix yet |
| Sep 21 | usbredir: out-of-bounds write | Medium4.1 | No fix yet |
| Sep 21 | Red Hat fetchmail: stack buffer overflow | High8.1 | No fix yet |
| Sep 21 | Red Hat pki-core: improper authorization | High8.1 | No fix yet |
| Sep 21 | Red Hat OpenShift Container Platform 4: improper signature check | High7.4 | No fix yet |
| Sep 21 | Red Hat Openshift Data Foundation 4: improper signature check | High7.1 | No fix yet |