Executive brief
The Quarkus OpenAPI Generator, a tool used to automatically create web service clients, contains a flaw in how it handles security credentials. When a developer uses this tool to connect to multiple services, the generated code may mistakenly send sensitive information like API keys or login tokens to the wrong web address. This could lead to the exposure of private access credentials to unauthorized third-party servers.
Technical details
A vulnerability exists in the Quarkus OpenAPI Generator where the generated authentication filter uses overly broad path-template matching. The root cause is that the runtime authentication layer treats OpenAPI {param} placeholders as a greedy regular expression (.*), which incorrectly allows a single path parameter to consume forward slashes (/). Consequently, a security scheme intended for a specific protected path (e.g., /repos/{ref}) may be incorrectly applied to a different, unprotected path (e.g., /repos/foo/bar). An attacker who can influence the client to call these similar-looking but unintended endpoints can capture bearer tokens, API keys, or basic authentication credentials. The issue is patched in versions 2.11.1-lts, 2.16.0-lts, and 2.17.0.
Affected products
- Quarkiverse quarkus-openapi-generator < 2.11.1-lts, < 2.16.0-lts, < 2.17.0
Timeline
- 2026-04-23: advisory: GitHub Security Advisory published by maintainers
- 2026-04-27: patched: Security patch released in version 2.11.1-lts
- 2026-05-09: disclosed: CVE-2026-42333 published to NVD
References
- https://github.com/quarkiverse/quarkus-openapi-generator/pull/1586
- https://github.com/quarkiverse/quarkus-openapi-generator/releases/tag/2.11.1-lts
- https://github.com/quarkiverse/quarkus-openapi-generator/releases/tag/2.16.0-lts
- https://github.com/quarkiverse/quarkus-openapi-generator/releases/tag/2.17.0
- https://github.com/quarkiverse/quarkus-openapi-generator/security/advisories/GHSA-fr8f-rwjx-f32v