Medium severity5.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108748
CVE-2026-108748
Description
Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.9.0 - 1.14.1
Patches
Vulnerability mechanics
References
4- github.com/quarkiverse/quarkus-langchain4j/blob/658ac8268e1a453a6a2066952d9495fb925479e3/chat-scopes/core/runtime/src/main/java/io/quarkiverse/langchain4j/chatscopes/internal/ChatScopeManagedContext.javanvd
- github.com/quarkiverse/quarkus-langchain4j/blob/658ac8268e1a453a6a2066952d9495fb925479e3/chat-scopes/websocket/runtime/src/main/java/io/quarkiverse/langchain4j/chatscopes/websocket/internal/ChatRouteEndpoint.javanvd
- hackmd.io/@haind/quarkus-langchain4j-chatscope-orphan-leaknvd
- www.vulncheck.com/advisories/quarkus-langchain4j-1.9.0-through-1.14.1-memory-exhaustion-via-chat-routes-websocketnvd
News mentions
0No linked articles in our index yet.