PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66560 quarkusio CVE debrief

A vulnerability in Quarkus REST's HTTP layer can cause worker threads to become permanently blocked if client connections are dropped during response handling, potentially leading to degraded performance or application unavailability. This issue arises when the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked. Under sustained or repeated occurrences, this can exhaust the available worker threads, leading to degraded performance or complete unavailability of the application.

Vendor
quarkusio
Product
quarkus
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders and developers using Quarkus REST should assess exposure and apply patches or workarounds to prevent thread exhaustion, which can lead to performance degradation or application unavailability. They should review and update Quarkus versions to ensure patched versions are used and implement a health check to monitor worker thread pool status and saturation.

Why it matters

Defenders and developers using Quarkus REST should assess exposure and apply patches or workarounds to prevent thread exhaustion, which can lead to performance degradation or application unavailability.

  • Potential for degraded application performance due to thread pool exhaustion
  • Risk of complete application unavailability under sustained or repeated attacks
  • Need for verification of Quarkus versions and patch application
  • Importance of monitoring worker thread pool status and saturation

Technical summary

The Quarkus REST HTTP layer vulnerability causes worker threads to become permanently blocked if client connections are dropped during response handling. This can lead to thread pool exhaustion, degrading performance or causing application unavailability. The issue arises when the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked.

Defensive priority

Apply patches or workarounds to prevent thread exhaustion

Recommended defensive actions

  • Apply patches (versions 3.31.0, 3.27.2, or 3.20.5) to prevent thread exhaustion
  • Implement a health check to monitor worker thread pool status and saturation
  • Review and update Quarkus versions to ensure patched versions are used
  • Verify the existence of affected product deployments in managed environments
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and patches. A vendor advisory is also available. The vulnerability exists in the HTTP layer of Quarkus REST related to response handling. Defenders and developers using Quarkus REST should assess exposure and apply patches or workarounds to prevent thread exhaustion. The issue has been patched in versions 3.31.0, 3.27.2, and 3.20.5.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66560 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66560

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66560 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66560

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.