Description
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
Problem types
Missing Release of Resource after Effective Lifetime
Product status
Timeline
| 2025-12-19: | Reported to Red Hat. |
| 2025-12-19: | Made public. |
References
access.redhat.com/errata/RHSA-2026:1965 (RHSA-2026:1965)
access.redhat.com/security/cve/CVE-2025-14969
bugzilla.redhat.com/show_bug.cgi?id=2423822 (RHBZ#2423822)