VYPR
High severity7.5NVD Advisory· Published Jun 19, 2026· Updated Aug 13, 2026

CVE-2026-50559

CVE-2026-50559

Description

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.quarkus:quarkus-vertx-httpMaven
< 3.20.6.23.20.6.2
io.quarkus:quarkus-vertx-httpMaven
>= 3.21.0.CR1, < 3.27.4.13.27.4.1
io.quarkus:quarkus-vertx-httpMaven
>= 3.28.0.CR1, < 3.33.2.13.33.2.1
io.quarkus:quarkus-vertx-httpMaven
>= 3.34.0.CR1, < 3.36.33.36.3
io.quarkus:quarkus-vertx-httpMaven
>= 3.37.0.CR1, < 3.37.03.37.0

Affected products

24

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.