Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the sec…
High CVSS 8.2
Summary
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Quarkus's security layer performs authorization checks on the raw URL path which preserves matrix parameters (semicolons), while RESTEasy Reactive's routing layer stri…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/quarkusio/quarkus/security/advisories/GHSA-rc95-pcm8-65v9 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:11720
- https://access.redhat.com/errata/RHSA-2026:11721
- https://access.redhat.com/errata/RHSA-2026:13631
- https://access.redhat.com/errata/RHSA-2026:17789
- https://access.redhat.com/errata/RHSA-2026:25089
- https://access.redhat.com/errata/RHSA-2026:34608
- https://access.redhat.com/errata/RHSA-2026:54435
- https://access.redhat.com/security/cve/CVE-2026-39852
- https://bugzilla.redhat.com/show_bug.cgi?id=2457819
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39852.json
Timeline
- nvd_ingest NVD