---
id: CVE-2026-87743
title: A flaw was found in Quarkus HTTP security
summary: >-
  A flaw was found in Quarkus HTTP security. An unauthenticated attacker can
  exploit a discrepancy in how paths are normalized between the security matcher
  and HTTP request dispatchers. This allows the attacker to craft a URL that the
  secu…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-551
vendor: Red Hat
product: exploit-intelligence/agent-client-rhel9
affected:
  - exploit-intelligence/agent-client-rhel9
  - openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9
  - openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9
  - openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9
  - openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9
  - openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9
  - openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9
  - openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9
  - openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9
  - quarkus-vertx-http
  - quarkus-vertx-http
  - quarkus-vertx-http
  - keycloak/rhbk-openshift-rhel9
  - keycloak/rhbk-rhel9-operator
  - quarkus-vertx-http
  - rhbk/keycloak-rhel9
  - rhbk/keycloak-rhel9-operator
  - quarkus-vertx-http
  - rhoai/odh-trustyai-service-rhel9
  - devspaces/multicluster-redirector-rhel9
published: '2026-09-18'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:19:14.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87743'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:69470'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-87743'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2530523'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87743.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-87743'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87743'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00429
epssPercentile: 0.36645
ingestedAt: '2026-09-18T10:39:24.458Z'
---

## Overview

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the security matcher considers public, but which is then routed to a protected endpoint, leading to an authorization bypass and potential unauthorized access to sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat Fuse 7, Exploit Intelligence, … · no fix planned: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-87743.json)
