OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94449

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The SmallRye Fault Tolerance library, utilized by Quarkus for microservices, contains a flaw that prevents the release of internal tracking objects when using ApplyGuard or ApplyFaultTolerance annotations. This memory leak can result in increased memory consumption, ultimately causing application performance degradation and crashes due to exhaustion of available memory. Organizations leveraging Quarkus for microservices should prioritize addressing this vulnerability to maintain application stability and performance.

CVE
CVE-2026-94449
Severity
HIGH
CVSS
7.5
EPSS
0.49%

Original NVD Description

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory.