VYPR

quarkus-langchain4j

by Quarkiverse

CVEs (1)

  • CVE-2026-108748MedOct 11, 2026
    risk 0.34cvss 5.3epss —

    Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId,…