VYPR
Vendor

Quarkusio

Products
4
CVEs
58
Across products
58
Status
Private

Products

4

Recent CVEs

58
View all 58 CVEs →
  • CVE-2022-4116CriNov 22, 2022
    risk 0.66cvss 9.8epss 0.33

    A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

  • CVE-2022-2466CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

  • CVE-2024-12225CriMay 6, 2025
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST…

  • CVE-2022-0981HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.

  • CVE-2023-6267HigJan 25, 2024
    risk 0.56cvss 8.6epss 0.01

    A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with…

  • CVE-2023-4853HigSep 20, 2023
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting…

  • CVE-2021-26291CriApr 23, 2021
    risk 0.53cvss 9.1epss 0.09

    Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to…

  • CVE-2021-29427HigApr 13, 2021
    risk 0.52cvss 8.0epss 0.01

    In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve…

  • CVE-2017-18640HigDec 12, 2019
    risk 0.51cvss 7.5epss 0.27

    The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

  • CVE-2023-5720HigNov 15, 2023
    risk 0.50cvss 7.7epss 0.01

    A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

  • CVE-2020-1714HigMay 13, 2020
    risk 0.50cvss 8.8epss 0.03

    A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially…

  • CVE-2026-16308HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

  • CVE-2022-4147HigDec 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no…

  • CVE-2021-37714HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.07

    jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop…

  • CVE-2025-1247HigFeb 13, 2025
    risk 0.47cvss 8.3epss 0.01

    A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

  • CVE-2026-39852HigMay 5, 2026
    risk 0.46cvss 8.2epss 0.00

    Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged…

  • CVE-2022-21363MedJan 19, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2020-25649HigDec 3, 2020
    risk 0.43cvss 7.5epss 0.18

    A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

  • CVE-2020-13692HigJun 4, 2020
    risk 0.43cvss 7.7epss 0.04

    PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

  • CVE-2026-50559HigJun 19, 2026
    risk 0.42cvss 7.5epss 0.00

    Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past…