Sceawere

Vulnerability Detail

CVE-2026-108748UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Quarkus LangChain4j Memory Exhaustion

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
quarkiverse
Product
quarkus-langchain4j
Attack Type
Missing Release of Memory after Effective Lifetime
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-11T13:17:19.523Z",
  "pubdate": "2026-10-11T13:17:19.523Z",
  "executiveSummary": "Quarkus LangChain4j versions 1.9.0 through 1.14.1 are susceptible to a memory leak vulnerability located within the WebSocket chat-scopes implementation at the /_chat/routes endpoint.\nThis vulnerability is classified as a missing release of memory defect, which allows an unauthenticated, remote attacker to trigger an out-of-memory condition on the host JVM.\nThe flaw stems from the improper management of chat session scopes, where the lifecycle of WebSocket connections does not correctly clean up associated memory allocations in the activeScopes registry.\nBy repeatedly sending CONNECT frames using the same chatId, an attacker can force the application to retain orphaned references, leading to heap exhaustion and a subsequent denial-of-service (DoS) state.\nThe vulnerability poses a significant risk to availability, as it does not require prior authentication or privileged access to exploit, and can be triggered entirely over the network via standard WebSocket traffic.\nSuccessful exploitation results in service degradation or total process termination, impacting the reliability of applications utilizing the affected LangChain4j extensions.",
  "technicalDetails": "The vulnerability resides in the management of chat session scopes within the Quarkus LangChain4j WebSocket integration, specifically affecting the /_chat/routes endpoint. The root cause is a resource management flaw where the application fails to properly deallocate or release memory objects associated with chat sessions after a WebSocket connection is initiated or re-negotiated.\nThe internal component responsible for tracking active chat scopes, referred to as activeScopes, maintains references to objects associated with a specific chatId. When an attacker initiates a WebSocket connection, a new scope is created. The implementation is vulnerable because it allows for the repeated submission of CONNECT frames that force the application to allocate new objects or fail to overwrite existing entries in the tracking registry.\nAn attacker can systematically exploit this by crafting a sequence of WebSocket frames that target the /_chat/routes endpoint. By sending multiple CONNECT frames while reusing the same chatId, the attacker forces the system to orphan the previous scope reference while failing to nullify or garbage-collect the underlying data structures. Because these orphaned objects remain referenced by the activeScopes map, the Java Garbage Collector (GC) is prevented from reclaiming the associated heap space.\nAs the attacker continues to flood the endpoint with these requests, the heap usage monotonically increases. This behavior creates a persistent memory leak that persists until the JVM is manually restarted or crashes due to an OutOfMemoryError. The network exposure is broad, as the endpoint is accessible to any remote entity capable of establishing a WebSocket connection with the server.\nExploitation does not require authentication or specific system privileges, making it a high-utility vector for DoS attacks. Post-exploitation, the server enters a state of resource starvation, which causes severe performance degradation, increased latency for legitimate users, and eventual service failure. The vulnerability affects all versions of Quarkus LangChain4j from 1.9.0 up to and including 1.14.1."
}
CVE-2026-108748: Quarkus LangChain4j Memory Exhaustion (MEDIUM Severity, CVSS: 5.3) | Sceawere