VDB

CVE-2026-16308

CVE-2026-16308 PUBLISHED CVSS 7.5 HIGH

Reported by ibm · Published July 30, 2026

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
IBMEnterprise Build of Quarkus3.27.1, 3.33.1
IBMEnterprise Build of Quarkus3.27.1, 3.33.1

Timeline

  • Jul 29, 2026 CVE Published
  • Jul 29, 2026 Distribution Patch
  • Jul 29, 2026 Security Advisory
  • Jul 30, 2026 Distribution Patch
  • Jul 30, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 7, 2026 Distribution Patch
  • Aug 7, 2026 Security Advisory
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Security Advisory
  • Aug 8, 2026 Distribution Patch
  • Aug 8, 2026 Security Advisory

References

  • vendor-advisorypatch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›