Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frpp-8pwq-hjrx

Опубликовано: 26 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion

A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.

Пакеты

Наименование

org.hibernate.reactive:hibernate-reactive-core

maven
Затронутые версииВерсия исправления

< 4.2.1

4.2.1

EPSS

Процентиль: 2%
0.00014
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-772

Связанные уязвимости

CVSS3: 4.3
nvd
11 дней назад

A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.

EPSS

Процентиль: 2%
0.00014
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-772