CVE-2025-49574
Description
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential data leak when duplicating a duplicated context. Quarkus extensively uses the Vert.x duplicated context to implement context propagation. With the new semantic data from one transaction can leak to the data from another transaction. From a Vert.x point of view, this new semantic clarifies the behavior. A significant amount of data is stored in the duplicated context, including request scope, security details, and metadata. Duplicating a duplicated context is rather rare and is only done in a few places. This issue has been patched in version 3.24.1, 3.20.2, and 3.15.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.quarkus:quarkus-vertxMaven | < 3.15.6 | 3.15.6 |
io.quarkus:quarkus-vertxMaven | >= 3.16.0.CR1, < 3.20.2 | 3.20.2 |
io.quarkus:quarkus-vertxMaven | >= 3.21.0.CR1, < 3.24.1 | 3.24.1 |
Affected products
4- osv-coords3 versionspkg:apk/chainguard/knative-kafka-broker-1.17-dispatcher-loompkg:apk/chainguard/knative-kafka-broker-1.17-receiver-loompkg:maven/io.quarkus/quarkus-vertx
< 1.17.3-r7+ 2 more
- (no CPE)range: < 1.17.3-r7
- (no CPE)range: < 1.17.3-r7
- (no CPE)range: < 3.15.6
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-9623-mj7j-p9v4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-49574ghsaADVISORY
- github.com/quarkusio/quarkus/commit/2b58f59f4bf0bae7d35b1abb585b65f2a66787d1nvdWEB
- github.com/quarkusio/quarkus/commit/31e8a3bfcf4e223788615d5ce25eb929ca251275nvdWEB
- github.com/quarkusio/quarkus/commit/d1ee57e7b826872b6355cfec0ae13465840e232cnvdWEB
- github.com/quarkusio/quarkus/issues/48227nvdWEB
- github.com/quarkusio/quarkus/pull/48486nvdWEB
- github.com/quarkusio/quarkus/releases/tag/3.24.1nvdWEB
- github.com/quarkusio/quarkus/security/advisories/GHSA-9623-mj7j-p9v4nvdWEB
News mentions
0No linked articles in our index yet.