Flaw in Hibernate Reactive Allows Database Connection Pool Exhaustion
CVE-2025-14969

4.3MEDIUM

What is CVE-2025-14969?

A vulnerability exists in Hibernate Reactive whereby an exposed HTTP endpoint performing database operations can be impacted by a remote client prematurely closing the HTTP connection. This action risks leaking connections from the database connection pool, which can consequently lead to service disruptions as available database connections are exhausted, potentially resulting in a Denial of Service scenario.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.