CVE Tools

Quarkus

14 CVEs tracked since 2020. Since Dec 2020, none of them reached CISA KEV.

Quarkus CVEs per month

Dec 2020 to Oct 2021. Point at a month, or focus the strip and use the arrow keys.
Quarkus CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-1240
2021-01null or fewer
2021-0230
2021-03null or fewer
2021-0440
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-1030

Products

The products that kept showing up in Quarkus's monthly top three, with their CVEs summed over those months.

  1. Quarkus144 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Quarkus.

  1. CVE-2026-12894Io.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine8.8
  2. CVE-2026-50559Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities7.5
  3. CVE-2026-39852Quarkus authorization bypass via semicolon path normalization inconsistency8.2
  4. CVE-2025-66560Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write5.9
  5. CVE-2024-12225Io.quarkus:quarkus-security-webauthn: quarkus webauthn unexpected authentication bypass9.1
  6. CVE-2023-6267Quarkus: json payload getting processed prior to security checks when rest resources are used with annotations.8.6
  7. CVE-2023-6394Quarkus: graphql operations over websockets bypass7.4
  8. CVE-2023-5720Quarkus: build env information disclosure via gradle plugin7.7
  9. CVE-2023-1584Quarkus-oidc: id and access tokens leak via the authorization code flow7.5
  10. CVE-2023-4853Quarkus: http security policy bypass8.1
  11. CVE-2023-0481In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a loc...3.3
  12. CVE-2023-0044If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented...6.1
  13. CVE-2022-4147Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on...7.5
  14. CVE-2022-4116A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.9.8
  15. CVE-2022-42004In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An applicat...7.5

The record

Peak rank
#128 in Apr 2021
Busiest month shown
Dec 2020, 4 CVEs
Months with a KEV entry
0 since Dec 2020
Monthly snapshots
4 since 2020
Quarkus's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store