{"id":"CVE-2026-87742","title":"A flaw was found in quarkus-websockets-next","summary":"A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded mes…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770"],"vendor":"Red Hat","product":"exploit-intelligence/agent-client-rhel9","affected":["exploit-intelligence/agent-client-rhel9 (all versions)","rhelai3/bootc-cuda-rhel9 (all versions)","rhelai3/bootc-gaudi-rhel9 (all versions)","rhelai3/bootc-rocm-rhel9 (all versions)","rhelai3/disk-image-cuda-rhel9 (all versions)"],"published":"2026-09-17","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:19:14.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87742","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:69470","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-87742","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530522","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87742.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87742"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87742"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-17T15:19:05.994572Z"},"epss":0.00332,"epssPercentile":0.26536,"ingestedAt":"2026-09-17T15:20:39.001Z","slug":"CVE-2026-87742","body":"## Overview\n\nA flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space, leading to a java.lang.OutOfMemoryError that crashes the Java Virtual Machine (JVM).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Exploit Intelligence, Red Hat Enterprise Linux AI (RHEL AI) 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87742.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}