Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked. Under sustained or repeated occurrences, this can exhaust the available worker threads, leading to degraded performance, or complete unavailability of the application. This issue has been patched in versions 3.31.0, 3.27.2, and 3.20.5. A workaround involves implementing a health check that monitors the status and saturation of the worker thread pool to detect abnormal thread retention early.
History

Thu, 08 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 08 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Quarkus
Quarkus quarkus
Vendors & Products Quarkus
Quarkus quarkus

Wed, 07 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 17:45:00 +0000

Type Values Removed Values Added
Description Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently blocked. Under sustained or repeated occurrences, this can exhaust the available worker threads, leading to degraded performance, or complete unavailability of the application. This issue has been patched in versions 3.31.0, 3.27.2, and 3.20.5. A workaround involves implementing a health check that monitors the status and saturation of the worker thread pool to detect abnormal thread retention early.
Title Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-07T17:59:59.091Z

Reserved: 2025-12-04T16:01:32.473Z

Link: CVE-2025-66560

cve-icon Vulnrichment

Updated: 2026-01-07T17:59:41.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-07T18:15:52.023

Modified: 2026-01-08T18:08:54.147

Link: CVE-2025-66560

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-01-08T00:00:00Z

Links: CVE-2025-66560 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-08T09:48:36Z