CVE-2025-14969: Red Hat Build Of Quarkus 3.27.2
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
Affected products
- Red Hat Red Hat Build Of Quarkus 3.27.2
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Openshift Dev Spaces
Published 2026-01-26. Last modified 2026-06-17.