PatchSiren cyber security CVE debrief
CVE-2026-94449 Red Hat CVE debrief
A memory leak vulnerability was found in the SmallRye Fault Tolerance library used by Quarkus. The flaw occurs when using ApplyGuard or ApplyFaultTolerance annotations, causing a steady increase in memory usage that eventually leads to application slowdown and crash due to lack of memory. This issue can cause significant performance degradation and potential denial-of-service conditions. Defenders should assess the impact on application stability and performance. The vulnerability affects Quarkus applications utilizing SmallRye Fault Tolerance.
- Vendor
- Red Hat
- Product
- Exploit Intelligence
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Quarkus applications using SmallRye Fault Tolerance should assess the potential impact of this vulnerability on application performance and stability. They should prioritize verifying the presence of this vulnerability, monitoring application memory usage, and considering updates to a fixed version of SmallRye Fault Tolerance. Additionally, defenders should review compensating controls and ensure appropriate monitoring and logging
Why it matters
Defenders should prioritize verifying the presence of this vulnerability in Quarkus applications using SmallRye Fault Tolerance and assess the potential impact on application performance and stability. The vulnerability can cause a steady increase in memory usage, leading to application slowdown and crash. Defenders should monitor application memory usage and consider updating to a fixed version of SmallRye Fault Tolerance.
- Potential application slowdown and crash due to memory exhaustion
- Increased risk of denial-of-service (DoS) attacks
- Need for verification of affected versions and deployment contexts
- Potential for data loss or corruption due to application instability
Technical summary
The SmallRye Fault Tolerance library used by Quarkus has a memory leak vulnerability. When using ApplyGuard or ApplyFaultTolerance annotations, the library fails to release internal tracking objects after each request, causing a steady increase in memory usage that eventually leads to application slowdown and crash due to lack of memory. This issue affects Quarkus applications that utilize SmallRye Fault Tolerance for fault tolerance strategies. The vulnerability can lead to performance degradation and potential denial-of-service conditions.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in Quarkus applications using SmallRye Fault Tolerance and assess the potential impact on application performance and stability.
Recommended defensive actions
- Verify the presence of SmallRye Fault Tolerance in Quarkus applications
- Assess the potential impact on application performance and stability
- Monitor application memory usage for unusual patterns
- Consider updating to a fixed version of SmallRye Fault Tolerance
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions, exploitation, and remediation is limited. Defenders should verify the presence of SmallRye Fault Tolerance in Quarkus applications and assess potential impacts. Evidence is based on CVE and NVD data, with limited additional context. Further verification tasks are recommended to determine affected scope and required mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94449 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94449
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94449 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94449
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-94449
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.