CVE-2026-16308
Awaiting Analysis Awaiting Analysis - Queue

IBM Quarkus REST Denial of Service via MIME Multipart Headers

Vulnerability report for CVE-2026-16308, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: IBM Corporation

Description

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm quarkus From 3.27.1 (inc) to 3.27.4.SP2 (inc)
ibm quarkus From 3.33.1 (inc) to 3.33.2.SP2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM Enterprise Build of Quarkus allows a remote attacker to cause a denial of service by sending specially crafted requests that cause unbounded accumulation of multipart MIME part-header bytes.

Detection Guidance

This vulnerability involves unbounded accumulation of multipart MIME part-header bytes in IBM Enterprise Build of Quarkus. Detection requires monitoring for unusual memory usage or network traffic patterns associated with multipart MIME processing. Check application logs for excessive header parsing attempts or memory exhaustion events. Use network monitoring tools to detect abnormal traffic volumes targeting REST endpoints.

Impact Analysis

The vulnerability can lead to system unavailability by consuming excessive memory and resources, potentially crashing the application or server handling the requests.

Compliance Impact

This vulnerability causes a denial of service due to unbounded accumulation of multipart MIME part-header bytes, which could disrupt services handling sensitive data. This may impact compliance with GDPR by affecting availability of personal data processing systems and HIPAA by disrupting healthcare-related services.

Mitigation Strategies

Upgrade IBM Enterprise Build of Quarkus to a version beyond 3.27.4.SP2 or 3.33.2.SP2 to address the unbounded multipart MIME part-header accumulation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16308. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart