VulnSea

quarkus vulnerabilities

CVEs whose affected-version data names the quarkus package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-50559High· 7.5
3mo ago

Quarkus is a Java framework for building cloud-native applications

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolo…

Twilightquarkus · quarkusEPSS 0.67%via NVD
CVE-2026-39852High· 8.2
4mo ago

Quarkus is a Java framework for building cloud-native applications

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allo…

Twilightquarkus · quarkusEPSS 0.48%via NVD
CVE-2023-4853High· 8.1
3y ago

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass …

Twilightquarkus · quarkusEPSS 1.4%via NVD
CVE-2020-25649High· 7.5
5y ago

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

Twilightfasterxml · jackson-databindEPSS 18%via NVD
quarkus vulnerabilities (CVEs) · VulnSea