Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Quarkus | Quarkus | * | 3.20.6.2 (excluding) |
| Quarkus | Quarkus | 3.21.0 (including) | 3.27.4.1 (excluding) |
| Quarkus | Quarkus | 3.28.0 (including) | 3.33.2.1 (excluding) |
| Quarkus | Quarkus | 3.34.0 (including) | 3.36.3 (excluding) |
| Cryostat 4 on RHEL 9 | RedHat | cryostat/cryostat-reports-rhel9:4.2.0-13 | * |
| Cryostat 4 on RHEL 9 | RedHat | cryostat/cryostat-rhel9:4.2.0-13 | * |
| Cryostat 4 on RHEL 9 | RedHat | cryostat/jfr-datasource-rhel9:4.2.0-13 | * |
| Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 | RedHat | quarkus-vertx-http | * |
| Red Hat build of Quarkus 3.20.6.SP2 | RedHat | quarkus-vertx-http | * |
| Red Hat build of Quarkus 3.27.4.SP1 | RedHat | quarkus-vertx-http | * |
| Red Hat build of Quarkus 3.33.2.SP1 | RedHat | quarkus-vertx-http | * |
| Streams for Apache Kafka 2.9.4 | RedHat | quarkus-vertx-http | * |
| Red Hat OpenShift Dev Spaces 3.29 | RedHat | devspaces/multicluster-redirector-rhel9:1782989027 | * |