CVE-2025-2240: Red Hat Build Of Apache Camel 4.8.5 For Spring Boot

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

Affected products

  • Red Hat Red Hat Build Of Apache Camel 4.8.5 For Spring Boot
  • Red Hat Red Hat Build Of Apache Camel 4.8 For Quarkus 3.15
  • Red Hat Red Hat Build Of Apicurio Registry 2
  • Red Hat Red Hat Build Of Apicurio Registry 3
  • Red Hat Red Hat Build Of Quarkus
  • Red Hat Red Hat Build Of Quarkus 3.15.4
  • Red Hat Red Hat Fuse 7
  • Red Hat Red Hat Integration Camel K 1
  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

Published 2025-03-12. Last modified 2026-08-13.