VYPR

Quarkus

by Red Hat

CVEs (3)

  • CVE-2024-12225CriMay 6, 2025
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST…

  • CVE-2026-12894HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive…

  • CVE-2026-87743HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the security matcher considers public, but which…