A flaw was found in Quarkus. A remote attacker could bypass HTTP path-based authorization policies by using specially crafted encoded semicolons, slashes, or backslashes in HTTP requests. This could allow unauthorized access to protected static resources, leading to information disclosure.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Quarkus. A remote attacker could bypass HTTP path-based authorization policies by using specially crafted encoded semicolons, slashes, or backslashes in HTTP requests. This could allow unauthorized access to protected static resources, leading to information disclosure. | |
| Title | io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters | |
| First Time appeared |
Redhat
Redhat apache Camel Quarkus Redhat quarkus |
|
| Weaknesses | CWE-551 | |
| CPEs | cpe:/a:redhat:apache_camel_quarkus:3.33 cpe:/a:redhat:quarkus:3.20::el8 cpe:/a:redhat:quarkus:3.27::el8 cpe:/a:redhat:quarkus:3.33::el8 |
|
| Vendors & Products |
Redhat
Redhat apache Camel Quarkus Redhat quarkus |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T19:00:11Z