CVE Tools

Red Hat Build of Quarkus

61 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Red Hat Build of Quarkus, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Build of Quarkus CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Build of Quarkus CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-022
2025-031
2025-040
2025-051
2025-060
2025-070
2025-080
2025-091
2025-100
2025-110
2025-121
2026-011
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-081
2026-095

Severity

How the 61 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical58%
  • High3252%
  • Medium2033%
  • Low47%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Build of Quarkus.

  1. CVE-2026-94449Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyguard leads to denial of service7.5
  2. CVE-2026-93432Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#eval} section in quarkus6.1
  3. CVE-2026-10832Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload5.9
  4. CVE-2026-89058Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config7.4
  5. CVE-2026-89059Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)7.5
  6. CVE-2026-76763Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of service via large exponent float literals7.5
  7. CVE-2024-4027Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacks7.5
  8. CVE-2024-3884Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded7.5
  9. CVE-2025-58057Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack7.5
  10. CVE-2024-12225Io.quarkus:quarkus-security-webauthn: quarkus webauthn unexpected authentication bypass9.1
  11. CVE-2025-2240Smallrye-fault-tolerance: smallrye fault tolerance7.5
  12. CVE-2025-1634Io.quarkus:quarkus-resteasy: memory leak in quarkus resteasy classic when client requests timeout7.5
  13. CVE-2025-24970SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine7.5
  14. CVE-2023-4639Undertow: cookie smuggling/spoofing7.4
  15. CVE-2023-6841Keycloak: amount of attributes per object is not limited and it may lead to dos7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store