๐Ÿ” CVE Alert

CVE-2026-39852

UNKNOWN 0.0

Quarkus authorization bypass via semicolon path normalization inconsistency

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Quarkus's security layer performs authorization checks on the raw URL path which preserves matrix parameters (semicolons), while RESTEasy Reactive's routing layer strips matrix parameters before matching endpoints. An attacker can append a semicolon and arbitrary text to a request URL (e.g., /api/admin;anything) to bypass policies protecting /api/admin while still routing to the protected endpoint. This issue has been fixed in versions 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2.

CWE CWE-863
Vendor quarkusio
Product quarkus
Published May 5, 2026
Stay Ahead of the Next One

Get instant alerts for quarkusio quarkus

Be the first to know when new unknown vulnerabilities affecting quarkusio quarkus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

quarkusio / quarkus
< 3.20.6.1 >= 3.27.3.0, < 3.27.3.1 >= 3.34.0, < 3.34.7 >= 3.35.0, < 3.35.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/quarkusio/quarkus/security/advisories/GHSA-rc95-pcm8-65v9