Home

Description

A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.

PUBLISHED Reserved 2025-12-19 | Published 2026-01-26 | Updated 2026-02-05 | Assigner redhat




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Problem types

Missing Release of Resource after Effective Lifetime

Product status

Default status
unaffected

Default status
unaffected

Default status
unaffected

Default status
unaffected

Default status
unaffected

Default status
unaffected

Default status
unaffected

Timeline

2025-12-19:Reported to Red Hat.
2025-12-19:Made public.

References

access.redhat.com/errata/RHSA-2026:1965 (RHSA-2026:1965) vendor-advisory

access.redhat.com/security/cve/CVE-2025-14969 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2423822 (RHBZ#2423822) issue-tracking

cve.org (CVE-2025-14969)

nvd.nist.gov (CVE-2025-14969)

Download JSON