Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50559

Опубликовано: 19 июн. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия до 3.20.6.2 (исключая)
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия от 3.21.0 (включая) до 3.27.4.1 (исключая)
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия от 3.28.0 (включая) до 3.33.2.1 (исключая)
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
Версия от 3.34.0 (включая) до 3.36.3 (исключая)

EPSS

Процентиль: 38%
0.00463
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-863
CWE-551

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 месяцев назад

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.

EPSS

Процентиль: 38%
0.00463
Низкий

7.5 High

CVSS3

Дефекты

CWE-287
CWE-863
CWE-551