CVE-2026-108748
Received Received - Intake

Quarkus LangChain4j Memory Exhaustion via WebSocket Chat Scopes

Vulnerability report for CVE-2026-108748, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
quarkiverse quarkus-langchain4j 1.9.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quarkus LangChain4j versions 1.9.0 to 1.14.1 have a missing release of memory vulnerability in the chat-scopes WebSocket endpoint. Unauthenticated remote attackers can send repeated CONNECT frames with the same chatId, creating orphaned scopes in activeScopes. This exhausts server memory until the JVM exits, degrading system availability.

Detection Guidance

Monitor for unusually high memory usage on the server running Quarkus LangChain4j. Check WebSocket connections to the /_chat/routes endpoint for repeated CONNECT frames with the same chatId. Use JVM tools like jcmd, jstack, or VisualVM to inspect active memory and thread states.

Impact Analysis

This vulnerability can lead to denial-of-service conditions where the server becomes unresponsive or crashes due to memory exhaustion. It may cause degraded performance, system outages, or require manual intervention to restart services.

Compliance Impact

This vulnerability primarily impacts availability by allowing memory exhaustion through orphaned WebSocket scopes. While not directly violating GDPR or HIPAA data protection requirements, it could indirectly affect compliance by degrading system performance or causing service disruptions that impact data processing operations. Organizations handling sensitive data under these regulations must ensure robust availability controls to maintain compliance.

Mitigation Strategies

Upgrade Quarkus LangChain4j to a version beyond 1.14.1. Implement rate limiting on the /_chat/routes WebSocket endpoint. Restrict unauthenticated access to this endpoint if possible. Monitor and kill orphaned chatId scopes manually if detected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108748. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart