Junglewise Threat Intelligence

CVE-2026-39852: Quarkus authorization bypass via semicolon in HTTP path

CVE-2026-39852 · Severity: high · CVSS 8.2 · Published 2026-05-05

Technologies: Red Hat Build of Apache Camel for Quarkus. Vendors: Red Hat.

Executive brief

Quarkus, a popular Java framework for building cloud-native applications, is affected by a security flaw that allows attackers to bypass access controls. By adding specific characters like semicolons to a web address, an unauthorized user can trick the system into granting access to restricted administrative or private data. This could lead to the exposure of sensitive information or unauthorized actions within the application.

Technical details

An authorization bypass exists in Quarkus due to a path-normalization inconsistency between the security layer and the RESTEasy Reactive routing layer. The security layer performs authorization checks on the raw URL path, which includes matrix parameters (e.g., /api/admin;anything), while the routing layer strips these parameters before matching endpoints. A remote, unauthenticated attacker can exploit this by appending a semicolon and arbitrary text to a request URL to bypass path-based security policies while still reaching the intended protected endpoint. The issue is addressed in Quarkus versions 3.20.6.1, 3.27.3.1, 3.33.1.1, and 3.35.1.1.

Affected products

  • Quarkus Quarkus Vert.x HTTP < 3.20.6.1, >= 3.21.0, < 3.27.3.1, >= 3.30.0, < 3.33.1.1, >= 3.34.0, < 3.35.1.1

Timeline

  • 2026-05-04: disclosed
  • 2026-05-04: advisory
  • 2026-05-04: patched

References

Related threats