CVE-2026-108748
MEDIUM
6,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low
Description
AI Translation Available
Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.
401
Missing Release of Memory after Effective Lifetime
DraftCommon Consequences
Security Scopes Affected:
Availability
Other
Potential Impacts:
Dos: Crash, Exit, Or Restart
Dos: Instability
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Reduce Performance
Applicable Platforms
Languages:
Not Language-Specific, C, C++
https://github.com/quarkiverse/quarkus-langchain4j
https://github.com/quarkiverse/quarkus-langchain4j/blob/658ac8268e1a453a6a20669…
https://github.com/quarkiverse/quarkus-langchain4j/blob/658ac8268e1a453a6a20669…
https://hackmd.io/@haind/quarkus-langchain4j-chatscope-orphan-leak
https://www.vulncheck.com/advisories/quarkus-langchain4j-1.9.0-through-1.14.1-m…