What is CVE-2026-16308?
A remote denial of service (DoS) vulnerability exists in IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.4.SP2 and 3.33.1 through 3.33.2.SP2 due to unbounded accumulation of multipart MIME part-header bytes in the Quarkus REST component. Affected systems should be updated to the latest patched versions to mitigate the issue.
Azərbaycanca: IBM Enterprise Build of Quarkus-un müəyyən versiyalarında Quarkus REST komponentində multipart MIME başlıq baytlarının məhdudiyyətsiz toplanması səbəbindən uzaqdan xidmət rəddi (DoS) zəifliyi aşkarlanıb. Bu, 3.27.1-3.27.4.SP2 və 3.33.1-3.33.2.SP2 versiyalarına təsir edir. Təsirə məruz qalan sistemlərdə müvafiq yeniləmələrin tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: IBM
FAQ2
In which functional component of IBM Enterprise Build of Quarkus does CVE-2026-16308 exist?
The vulnerability exists in the Quarkus REST component.
What is the root cause of this remote denial of service (DoS) issue?
The root cause is the unbounded accumulation of multipart MIME part-header bytes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.