GHSA-5rfx-cp42-p624

Suggest an improvement
Source
https://github.com/advisories/GHSA-5rfx-cp42-p624
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-5rfx-cp42-p624/GHSA-5rfx-cp42-p624.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5rfx-cp42-p624
Aliases
  • CVE-2025-66560
Published
2026-01-07T18:09:56Z
Modified
2026-01-07T20:45:04.374016Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
Details

A vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked. Under sustained or repeated occurrences, this can exhaust the available worker threads, leading to degraded performance, or complete unavailability of the application.

Workarounds

For versions without the fix applied, it is recommended to implement a health check that monitors the status and saturation of the worker thread pool. This helps detect abnormal thread retention early and allows operators to take corrective action before the application’s responsiveness is impacted.

Credits

CVE reported by Shaswata Jash, Nokia

Database specific
{
    "severity": "MODERATE",
    "github_reviewed_at": "2026-01-07T18:09:56Z",
    "cwe_ids": [
        "CWE-770"
    ],
    "nvd_published_at": "2026-01-07T18:15:52Z",
    "github_reviewed": true
}
References

Affected packages

Maven / io.quarkus:quarkus-rest

Package

Name
io.quarkus:quarkus-rest
View open source insights on deps.dev
Purl
pkg:maven/io.quarkus/quarkus-rest

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20.5

Affected versions

3.*

3.9.0.CR1
3.9.0.CR2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.5
3.10.0.CR1
3.10.0
3.10.1
3.10.2
3.11.0.CR1
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0.CR1
3.12.0
3.12.1
3.12.2
3.12.3
3.13.0.CR1
3.13.0
3.13.1
3.13.2
3.13.3
3.14.0.CR1
3.14.0
3.14.1
3.14.2
3.14.3
3.14.4
3.15.0.CR1
3.15.0
3.15.1
3.15.2
3.15.3
3.15.3.1
3.15.4
3.15.5
3.15.6
3.15.6.1
3.15.6.2
3.15.7
3.16.0.CR1
3.16.0
3.16.1
3.16.2
3.16.3
3.16.4
3.17.0.CR1
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.17.5
3.17.6
3.17.7
3.17.8
3.18.0.CR1
3.18.0
3.18.1
3.18.2
3.18.3
3.18.4
3.19.0.CR1
3.19.0
3.19.1
3.19.2
3.19.3
3.19.4
3.20.0.CR1
3.20.0
3.20.1
3.20.2
3.20.2.1
3.20.2.2
3.20.3
3.20.4

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-5rfx-cp42-p624/GHSA-5rfx-cp42-p624.json"

Maven / io.quarkus:quarkus-rest

Package

Name
io.quarkus:quarkus-rest
View open source insights on deps.dev
Purl
pkg:maven/io.quarkus/quarkus-rest

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.21.0
Fixed
3.27.2

Affected versions

3.*

3.21.0
3.21.1
3.21.2
3.21.3
3.21.4
3.22.0.CR1
3.22.0
3.22.1
3.22.2
3.22.3
3.23.0.CR1
3.23.0
3.23.1
3.23.2
3.23.3
3.23.4
3.24.0.CR1
3.24.0
3.24.1
3.24.2
3.24.3
3.24.4
3.24.5
3.25.0.CR1
3.25.0
3.25.1
3.25.2
3.25.3
3.25.4
3.26.0.CR1
3.26.0
3.26.1
3.26.2
3.26.3
3.26.4
3.27.0.CR1
3.27.0
3.27.1

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-5rfx-cp42-p624/GHSA-5rfx-cp42-p624.json"

Maven / io.quarkus:quarkus-rest

Package

Name
io.quarkus:quarkus-rest
View open source insights on deps.dev
Purl
pkg:maven/io.quarkus/quarkus-rest

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.30.0
Fixed
3.31.0

Affected versions

3.*

3.30.0
3.30.1
3.30.2
3.30.3
3.30.4
3.30.5
3.30.6

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-5rfx-cp42-p624/GHSA-5rfx-cp42-p624.json"