---
id: CVE-2024-12397
title: |-
  A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
  certain value-delimiting characters in incoming requests
summary: |-
  A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
  certain value-delimiting characters in incoming requests. This issue could
  allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
  values or spoo…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-444
published: '2024-12-12'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-12397'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:0900'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3018'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:8761'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-12397'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2331298'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12397.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-12397'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-12397'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00824
epssPercentile: 0.55504
ingestedAt: '2026-08-04T07:38:00.139Z'
vendor: Red Hat
product: Cryostat 4 on RHEL 9
affected:
  - cryostat 3
  - build_of_apache_camel_4_for_quarkus 3
  - build_of_apicurio_registry 2
  - build_of_keycloak
  - build_of_optaplanner 8
  - fuse 7
  - integration_camel_k 1
  - process_automation 7
  - streams_for_apache_kafka
  - cryostat_4_on_rhel 9
  - hawtio_hawtio 4.2.0
  - build_of_quarkus 3.15.3
patched:
  - cryostat_4_on_rhel 9
  - hawtio_hawtio 4.2.0
  - build_of_quarkus 3.15.3
---

## Overview

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with
certain value-delimiting characters in incoming requests. This issue could
allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie
values or spoof arbitrary additional cookie values, leading to unauthorized
data access or modification. The main threat from this flaw impacts data
confidentiality and integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:3018** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2025-03-19 · [advisory](https://access.redhat.com/errata/RHSA-2025:3018)
- **RHSA-2025:8761** · Red Hat · fixed in: HawtIO HawtIO 4.2.0 · released 2025-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:8761)
- **RHSA-2025:0900** · Red Hat · fixed in: Red Hat build of Quarkus 3.15.3 · released 2025-02-05 · [advisory](https://access.redhat.com/errata/RHSA-2025:0900)
- **Red Hat VEX** · Moderate · affected: Cryostat 3, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 2, Red Hat Build of Keycloak, Red Hat build of OptaPlanner 8, Red Hat Fuse 7, … · no fix planned: Red Hat Fuse 7, Red Hat build of OptaPlanner 8, Red Hat build of Apicurio Registry 2, Red Hat Build of Keycloak, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-12397.json)
