Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory. | |
| Title | Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyguard leads to denial of service | |
| First Time appeared |
Redhat
Redhat apicurio Registry Redhat camel Quarkus Redhat exploit Intelligence Redhat jboss Fuse Redhat quarkus |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:/a:redhat:apicurio_registry:3 cpe:/a:redhat:camel_quarkus:3 cpe:/a:redhat:exploit_intelligence:0 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:quarkus:3 |
|
| Vendors & Products |
Redhat
Redhat apicurio Registry Redhat camel Quarkus Redhat exploit Intelligence Redhat jboss Fuse Redhat quarkus |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-21T17:51:45.100Z
Reserved: 2026-09-21T16:45:10.036Z
Link: CVE-2026-94449
No data.
Status : Received
Published: 2026-09-21T17:19:20.097
Modified: 2026-09-21T18:17:17.050
Link: CVE-2026-94449
No data.
OpenCVE Enrichment
No data.