{"id":"CVE-2026-87743","title":"A flaw was found in Quarkus HTTP security","summary":"A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-551"],"vendor":"Red Hat","product":"exploit-intelligence/agent-client-rhel9","affected":["exploit-intelligence/agent-client-rhel9","openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9","openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9","openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9","openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9","openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9","openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9","openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9","openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9","quarkus-vertx-http","quarkus-vertx-http","quarkus-vertx-http","keycloak/rhbk-openshift-rhel9","keycloak/rhbk-rhel9-operator","quarkus-vertx-http","rhbk/keycloak-rhel9","rhbk/keycloak-rhel9-operator","quarkus-vertx-http","rhoai/odh-trustyai-service-rhel9","devspaces/multicluster-redirector-rhel9"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:19:14.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87743","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:69470","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-87743","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530523","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87743.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-87743"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87743"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00429,"epssPercentile":0.36645,"ingestedAt":"2026-09-18T10:39:24.458Z","slug":"CVE-2026-87743","body":"## Overview\n\nA flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the security matcher considers public, but which is then routed to a protected endpoint, leading to an authorization bypass and potential unauthorized access to sensitive information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Exploit Intelligence, … · no fix planned: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87743.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}