CVE-2026-59295
mediumEPSS Score
0.2%
Exploitation probability in 30 days
Top 87% most likely to be exploited
Published: August 24, 2026 (13 days ago)
Last Modified: August 24, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. connection resets or timeouts). Tracking state for these requests remains in memory indefinitely, and sustained failures lead to heap exhaustion and OutOfMemoryError crashes.
CWE
CWE-772Affected Products
Exploit IntelligenceRed Hat AMQ Broker 7Red Hat build of Apache Camel 4 for Quarkus 3Red Hat build of Apache Camel for Spring Boot 4Red Hat build of Apicurio Registry 3Red Hat build of Debezium 3Red Hat Build of KeycloakRed Hat build of QuarkusRed Hat Data Grid 8Red Hat Fuse 7