PT-2026-51029 · Quarkusio · Quarkus

Geoand

·

Published

2026-06-19

·

Updated

2026-06-19

·

CVE-2026-50559

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quarkus versions prior to 3.37.0 Quarkus versions prior to 3.36.3 Quarkus versions prior to 3.33.3 Quarkus versions prior to 3.33.2.1 Quarkus versions prior to 3.27.5 Quarkus versions prior to 3.27.4.1 Quarkus versions prior to 3.20.6.2
Description Quarkus, a Java framework for cloud-native applications, allows the bypass of HTTP path-based authorization policies. This can be achieved by using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, or by using encoded slashes (%2F) and backslashes (%5C) to gain unauthorized access to protected static resources.
Recommendations Update to version 3.37.0 Update to version 3.36.3 Update to version 3.33.3 Update to version 3.33.2.1 Update to version 3.27.5 Update to version 3.27.4.1 Update to version 3.20.6.2

Fix

Improper Authentication

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50559

Affected Products

Quarkus