IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

Project Subscriptions

Vendors Products
Enterprise Build Of Quarkus Subscribe
Quarkus Subscribe
Advisories

No advisories yet.

Fixes

Solution

The issues are addressed in IBM Enterprise Build of Quarkus 3.27.4.SP3 and 3.33.2.SP3. To update your project to IBM Enterprise Build of Quarkus 3.27.4.SP3 or 3.33.2.SP3, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .


Workaround

No workaround given by the vendor.

History

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus REST. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted multipart/form-data request with an excessively large header section. This unbounded accumulation of MIME part-header bytes can exhaust the Java Virtual Machine (JVM) heap memory, leading to an OutOfMemoryError. The primary consequence is a denial of service, causing the application to crash. IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
Title io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
First Time appeared Ibm
Ibm enterprise Build Of Quarkus
CPEs cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.4.sp2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.4.sp2:sp2:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.2.sp2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.2.sp2:sp2:*:*:*:*:*:*
Vendors & Products Ibm
Ibm enterprise Build Of Quarkus
References

Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus REST. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted multipart/form-data request with an excessively large header section. This unbounded accumulation of MIME part-header bytes can exhaust the Java Virtual Machine (JVM) heap memory, leading to an OutOfMemoryError. The primary consequence is a denial of service, causing the application to crash.
Title io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service
First Time appeared Redhat
Redhat quarkus
Weaknesses CWE-770
CPEs cpe:/a:redhat:quarkus:3.27::el8
Vendors & Products Redhat
Redhat quarkus
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T16:20:01.475Z

Reserved: 2026-07-20T14:31:00.798Z

Link: CVE-2026-16308

cve-icon Vulnrichment

Updated: 2026-07-30T16:19:56.091Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-29T13:19:42Z

Links: CVE-2026-16308 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T04:30:04Z

Weaknesses