Skip to content
MediumVulnerability

CVE-2026-108748: Quarkus LangChain4j memory exhaustion in chat-scopes WebSocket

Identifier
CVE-2026-108748
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

Quarkus LangChain4j versions 1.9.0 through 1.14.1 contain a missing-release-of-memory flaw in the chat-scopes WebSocket /_chat/routes endpoint. Unauthenticated remote clients can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.