Quarkus
14 CVEs tracked since 2020. Since Dec 2020, none of them reached CISA KEV.
Quarkus CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-12 | 4 | 0 |
| 2021-01 | null or fewer | |
| 2021-02 | 3 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | 4 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | 3 | 0 |
Products
The products that kept showing up in Quarkus's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Quarkus.
- CVE-2026-12894Io.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine8.8
- CVE-2026-50559Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities7.5
- CVE-2026-39852Quarkus authorization bypass via semicolon path normalization inconsistency8.2
- CVE-2025-66560Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write5.9
- CVE-2024-12225Io.quarkus:quarkus-security-webauthn: quarkus webauthn unexpected authentication bypass9.1
- CVE-2023-6267Quarkus: json payload getting processed prior to security checks when rest resources are used with annotations.8.6
- CVE-2023-6394Quarkus: graphql operations over websockets bypass7.4
- CVE-2023-5720Quarkus: build env information disclosure via gradle plugin7.7
- CVE-2023-1584Quarkus-oidc: id and access tokens leak via the authorization code flow7.5
- CVE-2023-4853Quarkus: http security policy bypass8.1
- CVE-2023-0481In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a loc...3.3
- CVE-2023-0044If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented...6.1
- CVE-2022-4147Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on...7.5
- CVE-2022-4116A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.9.8
- CVE-2022-42004In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An applicat...7.5
The record
- Peak rank
- #128 in Apr 2021
- Busiest month shown
- Dec 2020, 4 CVEs
- Months with a KEV entry
- 0 since Dec 2020
- Monthly snapshots
- 4 since 2020