Quarkus · Quarkus · CVE-2026-50559
**Name of the Vulnerable Software and Affected Versions**
Quarkus versions prior to 3.37.0
Quarkus versions prior to 3.36.3
Quarkus versions prior to 3.33.3
Quarkus versions prior to 3.33.2.1
Quarkus versions prior to 3.27.5
Quarkus versions prior to 3.27.4.1
Quarkus versions prior to 3.20.6.2
**Description**
Quarkus, a Java framework for cloud-native applications, allows the bypass of HTTP path-based authorization policies. This can be achieved by using encoded semicolons (`%3B`) to smuggle matrix parameters past the security layer, or by using encoded slashes (`%2F`) and backslashes (`%5C`) to gain unauthorized access to protected static resources.
**Recommendations**
Update to version 3.37.0
Update to version 3.36.3
Update to version 3.33.3
Update to version 3.33.2.1
Update to version 3.27.5
Update to version 3.27.4.1
Update to version 3.20.6.2