CVE-2025-14969: Red Hat Build Of Quarkus 3.27.2

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.

Affected products

  • Red Hat Red Hat Build Of Quarkus 3.27.2
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Openshift Dev Spaces

Published 2026-01-26. Last modified 2026-06-17.