CVE-2025-14969: Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
(updated )
A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potentially causing a Denial of Service (DoS) by exhausting available database connections.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-14969 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →