Executive brief
IBM Enterprise Build of Quarkus, a framework used for developing Java applications, is vulnerable to a denial-of-service attack. A remote attacker can send specially crafted web requests that cause the application to consume excessive memory, potentially leading to a complete system crash or service unavailability. This could disrupt business operations and impact the availability of customer-facing applications.
Technical details
A denial of service vulnerability exists in the Quarkus REST component of IBM Enterprise Build of Quarkus. The flaw is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling) and stems from the unbounded accumulation of multipart MIME part-header bytes. A remote, unauthenticated attacker can exploit this by sending a malicious multipart request with excessively large or numerous headers, leading to memory exhaustion. The vulnerability is addressed in versions 3.27.4.SP3 and 3.33.2.SP3.
Affected products
- IBM Enterprise Build of Quarkus 3.27.1 - 3.27.4.SP2, 3.33.1 - 3.33.2.SP2
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory
- 2026-07-30: patched