MEDIUM4.3
GHSA-frpp-8pwq-hjrx
Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
Quick fix
GHSA-frpp-8pwq-hjrx — org.hibernate.reactive:hibernate-reactive-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.2.1</version> for org.hibernate.reactive:hibernate-reactive-coreDetails
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.hibernate.reactive:hibernate-reactive-core
Introduced in:
0Fixed in: 4.2.1Fix
# pom.xml: bump <version>4.2.1</version> for org.hibernate.reactive:hibernate-reactive-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-14969[ADVISORY]
- https://github.com/hibernate/hibernate-reactive/commit/cd7f104e10de918004707ca0e26e3840976f780a[WEB]
- https://access.redhat.com/errata/RHSA-2026:1965[WEB]
- https://access.redhat.com/security/cve/CVE-2025-14969[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2423822[WEB]
- https://github.com/hibernate/hibernate-reactive[PACKAGE]