CVE-2025-2240

high Apache
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.9%
Exploitation probability in 30 days
Top 43% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
High
Published: March 12, 2025 (544 days ago)
Last Modified: August 4, 2026
Vendor: Apache
Source: MITRE

Description

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

CWE

CWE-1325

Affected Products

Red Hat Red Hat build of Apache Camel 4.8.5 for Spring BootRed Hat Red Hat Build of Apache Camel 4.8 for Quarkus 3.15Red Hat Red Hat build of Quarkus 3.15.4Red Hat Red Hat build of Apicurio Registry 2Red Hat Red Hat build of Apicurio Registry 3Red Hat Red Hat build of QuarkusRed Hat Red Hat Fuse 7Red Hat Red Hat Integration Camel K 1Red Hat Red Hat JBoss Enterprise Application Platform 7Red Hat Red Hat JBoss Enterprise Application Platform 8

References