CVE-2026-16308: IBM Enterprise Build Of Quarkus

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

Affected products

  • IBM Enterprise Build Of Quarkus: from 3.27.1, up to and including 3.27.4.SP2; from 3.33.1, up to and including 3.33.2.SP2

Published 2026-07-30. Last modified 2026-07-30.