Flaw in Hibernate Reactive Allows Database Connection Pool Exhaustion
CVE-2025-14969
4.3MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 26 January 2026
What is CVE-2025-14969?
A vulnerability exists in Hibernate Reactive whereby an exposed HTTP endpoint performing database operations can be impacted by a remote client prematurely closing the HTTP connection. This action risks leaking connections from the database connection pool, which can consequently lead to service disruptions as available database connections are exhausted, potentially resulting in a Denial of Service scenario.