quarkus has 4 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 8.1 (high). The most common weakness class is CWE-863 (3). Most affected products: quarkus (3), io.quarkus:quarkus-qute (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Weakness classes
Products
- quarkus 3
- io.quarkus:quarkus-qute 1
Worst active — by depth score
CVE-2026-12894High· 8.8A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails48CVE-2026-39852High· 8.2Quarkus is a Java framework for building cloud-native applications45CVE-2023-4853High· 8.1A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions45CVE-2026-50559High· 7.5Quarkus is a Java framework for building cloud-native applications41
quarkus vulnerabilities
CVEs affecting quarkus, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-12894High· 8.8A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails
A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails…
CVE-2026-50559High· 7.5Quarkus is a Java framework for building cloud-native applications
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolo…
CVE-2026-39852High· 8.2Quarkus is a Java framework for building cloud-native applications
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allo…
CVE-2023-4853High· 8.1A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass …