VYPR
High severity7.5NVD Advisory· Published Jun 18, 2026· Updated Jun 23, 2026

CVE-2025-53114

CVE-2025-53114

Description

CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 through 8.0.8, bad clients that always send a fixed batch value when the server is using the acknowledgement extension may cause the unacknowledged message queue to grow indefinitely, eventually causing an OutOfMemoryError. Versions 5.0.23, 6.0.19, 7.0.19, and 8.0.9 patch the issue. As a workaround, disable the acknowledgement extension.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.cometd.java:cometd-java-server-commonMaven
>= 5.0.0, < 5.0.235.0.23
org.cometd.java:cometd-java-server-commonMaven
>= 6.0.0, < 6.0.196.0.19
org.cometd.java:cometd-java-server-commonMaven
>= 7.0.0, < 7.0.197.0.19
org.cometd.java:cometd-java-server-commonMaven
>= 8.0.0, < 8.0.98.0.9

Affected products

1
  • CometD/CometDllm-fuzzy
    Range: 5.0.0 - 5.0.22, 6.0.0 - 6.0.18, 7.0.0 - 7.0.18, 8.0.0 - 8.0.8

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.