CVE-2025-53114: CometD has acknowledgement extension out of memory

Published Jun 10, 2026
·
Updated

Impact Bad clients that always send a fixed batch value while the server is using the acknowledgement extension can cause the unacknowledged message queue to grow indefinitely, eventually resulting in an OutOfMemoryError.

Such bad clients would always send:

json { "channel": "/meta/connect", ... "ext": { "ack": 1 } }

The server would never clear the unacknowledged message queue, and one bad client can cause a server outage.

Patches 5.0.x - https://github.com/cometd/cometd/pull/2168 6.0.x - https://github.com/cometd/cometd/pull/2169 8.0.x - https://github.com/cometd/cometd/pull/2118

Workarounds Disable the acknowledgement extension.

Resources https://github.com/cometd/cometd/discussions/2116 https://github.com/cometd/cometd/issues/2117

Other sources

CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 through 8.0.8, bad clients that always send a fixed batch value when the server is using the acknowledgement extension may cause the unacknowledged message queue to grow indefinitely, eventually causing an OutOfMemoryError. Versions 5.0.23, 6.0.19, 7.0.19, and 8.0.9 patch the issue. As a workaround, disable the acknowledgement extension.

MITRE

Affected Software

4 affected componentsFixes available
maven/org.cometd.java:cometd-java-server-common>=8.0.0<=8.0.8
8.0.9
maven/org.cometd.java:cometd-java-server-common>=7.0.0<=7.0.18
7.0.19
maven/org.cometd.java:cometd-java-server-common>=6.0.0<=6.0.18
6.0.19
maven/org.cometd.java:cometd-java-server-common>=5.0.0<=5.0.22
5.0.23

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.cometd.java:cometd-java-server-common to a version that resolves this vulnerability.

    Fixed in 8.0.9
  2. Upgrade

    Upgrade maven/org.cometd.java:cometd-java-server-common to a version that resolves this vulnerability.

    Fixed in 7.0.19
  3. Upgrade

    Upgrade maven/org.cometd.java:cometd-java-server-common to a version that resolves this vulnerability.

    Fixed in 6.0.19
  4. Upgrade

    Upgrade maven/org.cometd.java:cometd-java-server-common to a version that resolves this vulnerability.

    Fixed in 5.0.23
  5. Upgrade

    Upgrade cometd to a version that resolves this vulnerability.

    Fixed in 5.0.23
  6. Upgrade

    Upgrade cometd to a version that resolves this vulnerability.

    Fixed in 6.0.19
  7. Upgrade

    Upgrade cometd to a version that resolves this vulnerability.

    Fixed in 7.0.19
  8. Upgrade

    Upgrade cometd to a version that resolves this vulnerability.

    Fixed in 8.0.9
  9. Configuration

    As a workaround for the unacknowledged message queue growing indefinitely, disable the acknowledgement extension.

    CometD acknowledgement extension acknowledgement extension = disabled

Event History

Jun 10, 2026
Advisory Published
via GitHub·04:46 PM
Data Sourced
via GitHub·04:46 PM
DescriptionSeverityWeaknessAffected Software
Jun 18, 2026
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Sep 1, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-53114?

The severity of CVE-2025-53114 is rated as high, with a score of 7.5.

2

What is the impact of CVE-2025-53114?

CVE-2025-53114 can lead to an OutOfMemoryError due to clients sending fixed batch values causing the unacknowledged message queue to grow indefinitely.

3

How do I fix CVE-2025-53114?

To fix CVE-2025-53114, avoid allowing clients that do not properly handle message acknowledgements from connecting to the server.

4

Who is affected by CVE-2025-53114?

CVE-2025-53114 affects users of the CometD Java server who have clients that misbehave by sending fixed batch values.

5

When was CVE-2025-53114 published?

CVE-2025-53114 was published on June 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203