---
id: CVE-2023-4853
title: >-
  A flaw was found in Quarkus where HTTP security policies are not sanitizing
  certain character permutations correctly when accepting requests, resulting in
  incorrect evaluation of permissions
summary: >-
  A flaw was found in Quarkus where HTTP security policies are not sanitizing
  certain character permutations correctly when accepting requests, resulting in
  incorrect evaluation of permissions. This issue could allow an attacker to
  bypass …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-148
  - CWE-863
vendor: quarkus
product: quarkus
affected:
  - quarkus < 2.16.11
  - 'quarkus >= 3.2.0, < 3.2.6'
  - 'quarkus >= 3.3.0, < 3.3.3'
  - build_of_optaplanner = 8.0
  - 'build_of_quarkus >= 2.13.0, < 2.13.8'
  - decision_manager = 7.0
  - integration_camel_k < 1.10.2
  - integration_camel_quarkus
  - integration_service_registry
  - jboss_middleware = 1
  - jboss_middleware_text-only_advisories = 1.0
  - openshift_serverless
  - openshift_serverless = 1.0
  - process_automation_manager = 7.0
  - openshift_container_platform = 4.10
  - openshift_container_platform = 4.11
  - openshift_container_platform = 4.12
patched:
  - quarkus 3.3.3
  - build_of_quarkus 2.13.8
  - integration_camel_k 1.10.2
published: '2023-09-20'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4853'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:5170'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5310'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5337'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5446'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5479'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5480'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:6107'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:6112'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7653'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-4853'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/vulnerabilities/RHSB-2023-002'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2238034'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:5170'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5310'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5337'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5446'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5479'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:5480'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:6107'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:6112'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7653'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-4853'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/vulnerabilities/RHSB-2023-002'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2238034'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01437
epssPercentile: 0.72015
ingestedAt: '2026-08-04T18:41:06.016Z'
---

## Overview

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

## Affected

- `quarkus < 2.16.11`
- `quarkus >= 3.2.0, < 3.2.6`
- `quarkus >= 3.3.0, < 3.3.3`
- `build_of_optaplanner = 8.0`
- `build_of_quarkus >= 2.13.0, < 2.13.8`
- `decision_manager = 7.0`
- `integration_camel_k < 1.10.2`
- `integration_camel_quarkus`
- `integration_service_registry`
- `jboss_middleware = 1`
- `jboss_middleware_text-only_advisories = 1.0`
- `openshift_serverless`
- `openshift_serverless = 1.0`
- `process_automation_manager = 7.0`
- `openshift_container_platform = 4.10`
- `openshift_container_platform = 4.11`
- `openshift_container_platform = 4.12`

## Remediation

Upgrade past the affected range:

- `quarkus 3.3.3`
- `build_of_quarkus 2.13.8`
- `integration_camel_k 1.10.2`
