Executive brief
Quarkus, a popular Java framework for building cloud-native applications, is affected by a security flaw that allows attackers to bypass access controls. By adding specific characters like semicolons to a web address, an unauthorized user can trick the system into granting access to restricted administrative or private data. This could lead to the exposure of sensitive information or unauthorized actions within the application.
Technical details
An authorization bypass exists in Quarkus due to a path-normalization inconsistency between the security layer and the RESTEasy Reactive routing layer. The security layer performs authorization checks on the raw URL path, which includes matrix parameters (e.g., /api/admin;anything), while the routing layer strips these parameters before matching endpoints. A remote, unauthenticated attacker can exploit this by appending a semicolon and arbitrary text to a request URL to bypass path-based security policies while still reaching the intended protected endpoint. The issue is addressed in Quarkus versions 3.20.6.1, 3.27.3.1, 3.33.1.1, and 3.35.1.1.
Affected products
- Quarkus Quarkus Vert.x HTTP < 3.20.6.1, >= 3.21.0, < 3.27.3.1, >= 3.30.0, < 3.33.1.1, >= 3.34.0, < 3.35.1.1
Timeline
- 2026-05-04: disclosed
- 2026-05-04: advisory
- 2026-05-04: patched