---
id: CVE-2026-93432
title: A flaw was found in the Quarkus Qute template engine
summary: >-
  A flaw was found in the Quarkus Qute template engine. When the {#eval} section
  helper processes a sub-template, it fails to pass the parent template's
  content type information. This bypasses standard escaping mechanisms, allowing
  untrust…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: Red Hat
product: exploit-intelligence/agent-client-rhel9
affected:
  - exploit-intelligence/agent-client-rhel9 (all versions)
  - qute-core (all versions)
  - qute-generator (all versions)
  - qute-core (all versions)
  - qute-core (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - qute-core (all versions)
  - qute-generator (all versions)
  - qute-core (all versions)
  - qute-generator (all versions)
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:32.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93432'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-93432'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2536859'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93432.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-93432'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93432'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T19:48:06.603188Z'
ingestedAt: '2026-09-18T18:47:53.267Z'
epss: 0.00418
epssPercentile: 0.33335
---

## Overview

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat Build of Keycloak, Red Hat build of Quarkus, Red Hat Fuse 7 · no fix planned: Exploit Intelligence, Red Hat build of Apicurio Registry 3, Red Hat Fuse 7, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93432.json)
