CVE-2025-53114: Cometd

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 through 8.0.8, bad clients that always send a fixed batch value when the server is using the acknowledgement extension may cause the unacknowledged message queue to grow indefinitely, eventually causing an `OutOfMemoryError`. Versions 5.0.23, 6.0.19, 7.0.19, and 8.0.9 patch the issue. As a workaround, disable the acknowledgement extension.

Affected products

  • Cometd Cometd: from 5.0.0, before 5.0.23 (fixed in 5.0.23); from 6.0.0, before 6.0.19 (fixed in 6.0.19); from 7.0.0, before 7.0.19 (fixed in 7.0.19); from 8.0.0, before 8.0.9 (fixed in 8.0.9)

Published 2026-06-18. Last modified 2026-10-05.