PT-2026-51029 · Quarkus · Quarkus

·

CVE-2026-50559

·

Published

2026-06-19

·

Updated

2026-07-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quarkus versions prior to 3.37.0 Quarkus versions prior to 3.36.3 Quarkus versions prior to 3.33.3 Quarkus versions prior to 3.33.2.1 Quarkus versions prior to 3.27.5 Quarkus versions prior to 3.27.4.1 Quarkus versions prior to 3.20.6.2
Description Quarkus, a Java framework for cloud-native applications, allows the bypass of HTTP path-based authorization policies. This can be achieved by using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, or by using encoded slashes (%2F) and backslashes (%5C) to gain unauthorized access to protected static resources.
Recommendations Update to version 3.37.0 Update to version 3.36.3 Update to version 3.33.3 Update to version 3.33.2.1 Update to version 3.27.5 Update to version 3.27.4.1 Update to version 3.20.6.2

Fix

Incorrect Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CLEANSTART-2026-BK55944
CVE-2026-50559
GHSA-QCXP-GM7M-4J5V

Affected Products

Quarkus