PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94449 Red Hat CVE debrief

A memory leak vulnerability was found in the SmallRye Fault Tolerance library used by Quarkus. The flaw occurs when using ApplyGuard or ApplyFaultTolerance annotations, causing a steady increase in memory usage that eventually leads to application slowdown and crash due to lack of memory. This issue can cause significant performance degradation and potential denial-of-service conditions. Defenders should assess the impact on application stability and performance. The vulnerability affects Quarkus applications utilizing SmallRye Fault Tolerance.

Vendor
Red Hat
Product
Exploit Intelligence
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-25
Advisory published
2026-09-21
Advisory updated
2026-09-25

Who should care

Defenders responsible for Quarkus applications using SmallRye Fault Tolerance should assess the potential impact of this vulnerability on application performance and stability. They should prioritize verifying the presence of this vulnerability, monitoring application memory usage, and considering updates to a fixed version of SmallRye Fault Tolerance. Additionally, defenders should review compensating controls and ensure appropriate monitoring and logging

Why it matters

Defenders should prioritize verifying the presence of this vulnerability in Quarkus applications using SmallRye Fault Tolerance and assess the potential impact on application performance and stability. The vulnerability can cause a steady increase in memory usage, leading to application slowdown and crash. Defenders should monitor application memory usage and consider updating to a fixed version of SmallRye Fault Tolerance.

  • Potential application slowdown and crash due to memory exhaustion
  • Increased risk of denial-of-service (DoS) attacks
  • Need for verification of affected versions and deployment contexts
  • Potential for data loss or corruption due to application instability

Technical summary

The SmallRye Fault Tolerance library used by Quarkus has a memory leak vulnerability. When using ApplyGuard or ApplyFaultTolerance annotations, the library fails to release internal tracking objects after each request, causing a steady increase in memory usage that eventually leads to application slowdown and crash due to lack of memory. This issue affects Quarkus applications that utilize SmallRye Fault Tolerance for fault tolerance strategies. The vulnerability can lead to performance degradation and potential denial-of-service conditions.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in Quarkus applications using SmallRye Fault Tolerance and assess the potential impact on application performance and stability.

Recommended defensive actions

  • Verify the presence of SmallRye Fault Tolerance in Quarkus applications
  • Assess the potential impact on application performance and stability
  • Monitor application memory usage for unusual patterns
  • Consider updating to a fixed version of SmallRye Fault Tolerance
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions, exploitation, and remediation is limited. Defenders should verify the presence of SmallRye Fault Tolerance in Quarkus applications and assess potential impacts. Evidence is based on CVE and NVD data, with limited additional context. Further verification tasks are recommended to determine affected scope and required mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94449 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94449

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94449 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94449

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.