CVE-2025-2240 - CVE House
Back to Database
Status published High CVE-2025-2240

Smallrye-fault-tolerance: smallrye fault tolerance

Vulnerability Description

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2240

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat build of Apache Camel 4.8.5 for Spring Boot, Red Hat Build of Apache Camel 4.8 for Quarkus 3.15, Red Hat build of Quarkus 3.15.4, Red Hat build of Apicurio Registry 2, Red Hat build of Apicurio Registry 3, Red Hat build of Quarkus, Red Hat Fuse 7, Red Hat Integration Camel K 1, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack
Vulnerable Versions:
6.3.0, 6.5.0

Timeline

Official Publish: March 12th, 2025
Last Modified: May 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.