PT-2026-95587 · Red Hat · Exploit Intelligence+5
CVE-2026-93432
·
Published
2026-09-18
·
Updated
2026-09-27
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Quarkus Qute (affected versions not specified)
Description
A flaw in the Quarkus Qute template engine occurs when the
{#eval} section helper processes a sub-template and fails to pass the parent template's content type information. This failure bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This can lead to Cross-Site Scripting (XSS), where arbitrary code is executed in a user's browser, and JSON Injection, which allows for data manipulation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exploit Intelligence
Red Hat Build Of Keycloak
Red Hat Fuse 7
Red Hat Build Of Apache Camel 4 For Quarkus 3
Red Hat Build Of Apicurio Registry 3
Red Hat Build Of Quarkus