{"api_version":"1","generated_at":"2026-08-01T23:14:37+00:00","cve":"CVE-2026-16308","urls":{"html":"https://cve.report/CVE-2026-16308","api":"https://cve.report/api/cve/CVE-2026-16308.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16308","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16308"},"summary":{"title":"IBM Enterprise Build of Quarkus is affected by a DoS vulnerability","description":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-07-30 15:16:26","updated_at":"2026-07-30 17:16:28"},"problem_types":["CWE-770","CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7281904","name":"https://www.ibm.com/support/pages/node/7281904","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16308","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16308","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Enterprise Build of Quarkus","version":"affected 3.27.1 3.27.4.SP2 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Enterprise Build of Quarkus","version":"affected 3.33.1 3.33.2.SP2 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The issues are addressed in IBM Enterprise Build of Quarkus 3.27.4.SP3 and 3.33.2.SP3. To update your project to IBM Enterprise Build of Quarkus 3.27.4.SP3 or 3.33.2.SP3, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Mike Read (JP Morgan)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"16308","cve":"CVE-2026-16308","epss":"0.005490000","percentile":"0.428490000","score_date":"2026-07-31","updated_at":"2026-08-01 00:10:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-16308","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-30T16:19:53.535229Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-30T16:20:01.475Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.4.sp2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.4.sp2:sp2:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.2.sp2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.2.sp2:sp2:*:*:*:*:*:*"],"product":"Enterprise Build of Quarkus","vendor":"IBM","versions":[{"lessThanOrEqual":"3.27.4.SP2","status":"affected","version":"3.27.1","versionType":"semver"},{"lessThanOrEqual":"3.33.2.SP2","status":"affected","version":"3.33.1","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Mike Read (JP Morgan)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.</p>"}],"value":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T14:04:42.806Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7281904"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The issues are addressed in IBM Enterprise Build of Quarkus 3.27.4.SP3 and 3.33.2.SP3. To update your project to IBM Enterprise Build of Quarkus 3.27.4.SP3 or 3.33.2.SP3, follow the instructions in the <a href=\"https://www.ibm.com/docs/en/quarkus/3.27.x?topic=overview-learn-whats-new-in-327#proc_updating-quarkus-maven\" rel=\"nofollow\">product documentation</a>.</p>"}],"value":"The issues are addressed in IBM Enterprise Build of Quarkus 3.27.4.SP3 and 3.33.2.SP3. To update your project to IBM Enterprise Build of Quarkus 3.27.4.SP3 or 3.33.2.SP3, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x ."}],"title":"IBM Enterprise Build of Quarkus is affected by a DoS vulnerability"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-16308","datePublished":"2026-07-30T14:04:42.806Z","dateReserved":"2026-07-20T14:31:00.798Z","dateUpdated":"2026-07-30T16:20:01.475Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 15:16:26","lastModifiedDate":"2026-07-30 17:16:28","problem_types":["CWE-770","CWE-770 CWE-770 Allocation of Resources Without Limits or Throttling"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T16:19:53.535229Z","id":"CVE-2026-16308","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16308","Ordinal":"1","Title":"IBM Enterprise Build of Quarkus is affected by a DoS vulnerabili","CVE":"CVE-2026-16308","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16308","Ordinal":"1","NoteData":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.","Type":"Description","Title":"IBM Enterprise Build of Quarkus is affected by a DoS vulnerabili"}]}}}