CVE-2023-4853High· 8.1▾ TwilightA flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
1.2% → 1.4%
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
quarkus < 2.16.11quarkus >= 3.2.0, < 3.2.6quarkus >= 3.3.0, < 3.3.3build_of_optaplanner = 8.0build_of_quarkus >= 2.13.0, < 2.13.8decision_manager = 7.0integration_camel_k < 1.10.2integration_camel_quarkusintegration_service_registryjboss_middleware = 1jboss_middleware_text-only_advisories = 1.0openshift_serverlessopenshift_serverless = 1.0process_automation_manager = 7.0openshift_container_platform = 4.10openshift_container_platform = 4.11openshift_container_platform = 4.12Upgrade past the affected range:
quarkus 3.3.3build_of_quarkus 2.13.8integration_camel_k 1.10.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50559High· 7.5Quarkus is a Java framework for building cloud-native applications
CVE-2026-39852High· 8.2Quarkus is a Java framework for building cloud-native applications
CVE-2020-3578Medium· 5.3A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…
CVE-2024-6593Critical· 9.1Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…
CVE-2026-41048High· 7.1Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
CVE-2026-22822High· 8.8External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets