CVE-2026-16308

Summary

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

Affected Software

VendorProductVersion RangeStatus
IBMEnterprise Build of Quarkus3.27.1 <= 3.27.4.SP2affected
IBMEnterprise Build of Quarkus3.33.1 <= 3.33.2.SP2affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References