Known Vulnerabilities for products from Quarkus
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Quarkus".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94449 json | Not Provided | 2026-09-21 | 2026-09-25 | |
| CVE-2026-93432 json | Not Provided | 2026-09-18 | 2026-09-18 | |
| CVE-2026-88789 json | Not Provided | 2026-10-01 | 2026-10-01 | |
| CVE-2026-87743 json | Not Provided | 2026-09-18 | 2026-09-22 | |
| CVE-2026-87742 json | Not Provided | 2026-09-17 | 2026-09-22 | |
| CVE-2026-77874 json | Not Provided | 2026-09-24 | 2026-09-24 | |
| CVE-2026-68494 json | Not Provided | 2026-08-04 | 2026-08-05 | |
| CVE-2026-50559 json | Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.... | Not Provided | 2026-06-19 | 2026-08-13 |
| CVE-2026-39852 json | Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1... | Not Provided | 2026-05-05 | 2026-08-17 |
| CVE-2026-19651 json | Not Provided | 2026-09-08 | 2026-09-09 | |
| CVE-2025-66560 json | Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2,... | Not Provided | 2026-01-07 | 2026-09-30 |
| CVE-2023-6394 json | A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specifie... | Not Provided | 2023-12-09 | 2026-09-29 |
| CVE-2023-6267 json | 9.8 - CRITICAL | 2024-01-25 | 2024-01-31 | |
| CVE-2023-5720 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-15 | 2023-11-30 |
| CVE-2023-4853 json | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when acc... | Not Provided | 2023-09-20 | 2026-08-04 |
| CVE-2023-1584 json | A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure ... | 7.5 - HIGH | 2023-10-04 | 2023-11-07 |
| CVE-2023-0481 json | In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which ... | 3.3 - LOW | 2023-02-24 | 2023-03-07 |
| CVE-2023-0044 json | If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated whic... | 6.1 - MEDIUM | 2023-02-23 | 2023-03-03 |
| CVE-2022-42004 json | In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._... | 7.5 - HIGH | 2022-10-02 | 2022-12-02 |
| CVE-2022-42003 json | In FasterXML jackson-databind before 2.14.0-rc1, resource exhaustion can occur because of a lack of a check in primitive valu... | 7.5 - HIGH | 2022-10-02 | 2023-12-20 |
Known software with vulnerabilities from Quarkus
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Quarkus | Gizmo | 1.0.0 |
| Application | Quarkus | Quarkus | 0.0.1 |
| Application | Quarkus | Quarkus-http | 3.0.0 |
| Application | Quarkus | Quarkus-security | 1.0.0 |