Junglewise Threat Intelligence

CVE-2026-16308: IBM Enterprise Build of Quarkus denial of service in Quarkus REST

CVE-2026-16308 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

IBM Enterprise Build of Quarkus, a framework used for developing Java applications, is vulnerable to a denial-of-service attack. A remote attacker can send specially crafted web requests that cause the application to consume excessive memory, potentially leading to a complete system crash or service unavailability. This could disrupt business operations and impact the availability of customer-facing applications.

Technical details

A denial of service vulnerability exists in the Quarkus REST component of IBM Enterprise Build of Quarkus. The flaw is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling) and stems from the unbounded accumulation of multipart MIME part-header bytes. A remote, unauthenticated attacker can exploit this by sending a malicious multipart request with excessively large or numerous headers, leading to memory exhaustion. The vulnerability is addressed in versions 3.27.4.SP3 and 3.33.2.SP3.

Affected products

  • IBM Enterprise Build of Quarkus 3.27.1 - 3.27.4.SP2, 3.33.1 - 3.33.2.SP2

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory
  • 2026-07-30: patched

References