Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
Moderate severity
GitHub Reviewed
Published
Jan 26, 2026
to the GitHub Advisory Database
•
Updated Feb 5, 2026
Package
Affected versions
< 4.2.1
Patched versions
4.2.1
Description
Published by the National Vulnerability Database
Jan 26, 2026
Published to the GitHub Advisory Database
Jan 26, 2026
Reviewed
Jan 27, 2026
Last updated
Feb 5, 2026
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
References