REDHAT-BUG-2537502: High severity SmallRye Fault Tolerance core vulnerability

Published Sep 21, 2026
·
Updated

A memory leak vulnerability was discovered in SmallRye Fault Tolerance core. When a programmatic Guard, TypedGuard, or FaultTolerance is invoked through the ApplyGuard or the deprecated ApplyFaultTolerance annotations, the library retains one DelegatingMeteredOperation and one MetricsCollector instance per invocation for the lifetime of the singleton guard.

The root cause is that these objects are never released, causing the heap to grow linearly with the number of calls. An unauthenticated remote attacker can exploit this by sending a high volume of requests to a vulnerable endpoint, leading to increased garbage collection pressure, significant performance degradation, and an eventual OutOfMemoryError OOM condition. This impact occurs regardless of whether a description is set for the guard.

Affected Software

1 affected component
SmallRye Fault Tolerance core

Event History

Sep 21, 2026
Data Sourced
via Red Hat·04:45 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which applications are exposed to remote exploitation?

Applications are exposed when a vulnerable endpoint invokes a programmatic Guard, TypedGuard, or FaultTolerance through the ApplyGuard or deprecated ApplyFaultTolerance annotations. An unauthenticated remote attacker can trigger the issue by sending a high volume of requests to that endpoint.

2

Does setting a guard description prevent the issue?

No. The memory leak occurs regardless of whether a description is set for the guard.

3

How can operators recognize active impact?

Affected processes retain one DelegatingMeteredOperation and one MetricsCollector instance for each invocation for the lifetime of the singleton guard. Heap usage grows linearly with calls, which can produce increased garbage-collection pressure, performance degradation, and eventually an OutOfMemoryError.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203