← Zurück zur CVE-Suche

CVE-2026-39852

Quarkus

Beschreibung

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Quarkus-s security layer performs authorization checks on the raw URL path which preserves matrix parameters (semicolons), while RESTEasy Reactive-s routing layer strips matrix parameters before matching endpoints. An attacker can append a semicolon and arbitrary text to a request URL (e.g., /api/admin;anything) to bypass policies protecting /api/admin while still routing to the protected endpoint. This issue has been fixed in versions 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2.

CVSS 8.2EPSS 0.44400000000000006%Risiko 0.85
Quelle öffnen
Veröffentlicht
2026-05-05 21:16:22
Betroffene Versionen
<3.20.6.1, <3.27.3.1, <3.33.1.1, <3.35.1.1, <3.34.7, <3.35.2
Typ
Package
Zuletzt geändert
2026-08-04 13:18:32
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N