PT-2026-51029 · Quarkusio · Quarkus
Geoand
·
Published
2026-06-19
·
Updated
2026-06-19
·
CVE-2026-50559
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Quarkus versions prior to 3.37.0
Quarkus versions prior to 3.36.3
Quarkus versions prior to 3.33.3
Quarkus versions prior to 3.33.2.1
Quarkus versions prior to 3.27.5
Quarkus versions prior to 3.27.4.1
Quarkus versions prior to 3.20.6.2
Description
Quarkus, a Java framework for cloud-native applications, allows the bypass of HTTP path-based authorization policies. This can be achieved by using encoded semicolons (
%3B) to smuggle matrix parameters past the security layer, or by using encoded slashes (%2F) and backslashes (%5C) to gain unauthorized access to protected static resources.Recommendations
Update to version 3.37.0
Update to version 3.36.3
Update to version 3.33.3
Update to version 3.33.2.1
Update to version 3.27.5
Update to version 3.27.4.1
Update to version 3.20.6.2
Fix
Improper Authentication
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quarkus