A AegiFlow
MEDIUMCVSS 6.5EPSS 0.4%

CVE-2024-6875

Infinispan Potential Out of Memory Error via REST Compare API Buffer API

Published
2025-03-28
Modified
2026-07-21
EPSS percentile
36%
Aliases
GHSA-2q39-w2hw-2pjm
Sources
github-advisory

Summary

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.infinispan:infinispan-query

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.