PatchSiren cyber security CVE debrief
CVE-2025-66560 quarkusio CVE debrief
A vulnerability in Quarkus REST's HTTP layer can cause worker threads to become permanently blocked if client connections are dropped during response handling, potentially leading to degraded performance or application unavailability. This issue arises when the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked. Under sustained or repeated occurrences, this can exhaust the available worker threads, leading to degraded performance or complete unavailability of the application.
- Vendor
- quarkusio
- Product
- quarkus
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Defenders and developers using Quarkus REST should assess exposure and apply patches or workarounds to prevent thread exhaustion, which can lead to performance degradation or application unavailability. They should review and update Quarkus versions to ensure patched versions are used and implement a health check to monitor worker thread pool status and saturation.
Why it matters
Defenders and developers using Quarkus REST should assess exposure and apply patches or workarounds to prevent thread exhaustion, which can lead to performance degradation or application unavailability.
- Potential for degraded application performance due to thread pool exhaustion
- Risk of complete application unavailability under sustained or repeated attacks
- Need for verification of Quarkus versions and patch application
- Importance of monitoring worker thread pool status and saturation
Technical summary
The Quarkus REST HTTP layer vulnerability causes worker threads to become permanently blocked if client connections are dropped during response handling. This can lead to thread pool exhaustion, degrading performance or causing application unavailability. The issue arises when the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked.
Defensive priority
Apply patches or workarounds to prevent thread exhaustion
Recommended defensive actions
- Apply patches (versions 3.31.0, 3.27.2, or 3.20.5) to prevent thread exhaustion
- Implement a health check to monitor worker thread pool status and saturation
- Review and update Quarkus versions to ensure patched versions are used
- Verify the existence of affected product deployments in managed environments
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and patches. A vendor advisory is also available. The vulnerability exists in the HTTP layer of Quarkus REST related to response handling. Defenders and developers using Quarkus REST should assess exposure and apply patches or workarounds to prevent thread exhaustion. The issue has been patched in versions 3.31.0, 3.27.2, and 3.20.5.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66560 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66560
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66560 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66560
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/quarkusio/quarkus/security/advisories/GHSA-5rfx-cp42-p624
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.