MediumVulnerability
CVE-2026-108748: Quarkus LangChain4j memory exhaustion in chat-scopes WebSocket
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108748
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
Quarkus LangChain4j versions 1.9.0 through 1.14.1 contain a missing-release-of-memory flaw in the chat-scopes WebSocket /_chat/routes endpoint. Unauthenticated remote clients can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database