CVE-2025-2240 describes an out-of-memory (OOM) vulnerability in Smallrye's smallrye-fault-tolerance component. This flaw is triggered by external calls to the metrics URI, where each call creates a new object in meterMap, leading to a denial of service (DoS) condition. With a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and no user interaction required, resulting in high availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Build Of Apicurio Registry 3 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Integration Camel K 1 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Fuse 7 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat Build Of Apicurio Registry 2 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.