Quarkus Path Authorization Bypass via Encoded Semicolon (CVE-2026-50558) with POC
Security AdvisoryCVE-2026-50558CriticalQuarkus
Affected:
- io.quarkus:quarkus-vertx-http<=3.5.1.1
- io.quarkus:quarkus-vertx-http<=3.27.3.1
- io.quarkus:quarkus-vertx-http<=3.20.6.1
- io.quarkus:quarkus-vertx-http<=3.33.1.1
- io.quarkus:quarkus-vertx-http<=3.35.2
Fixed in:
- 3.37.0
- 3.38.3
- 3.33.2.1
- 3.33.3
- 3.27.4.1
Referenced CVEs: CVE-2026-50559 · 7.5
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.