Junglewise Threat Intelligence

CVE-2026-87743: Red Hat Quarkus authorization bypass via path normalization discrepancy

CVE-2026-87743 · Severity: high · CVSS 7.5 · Published 2026-09-18

Vendors: Red Hat.

Executive brief

Red Hat Quarkus is a popular Java framework used to build enterprise applications and microservices. An unauthenticated attacker can bypass authorization controls by exploiting how the framework normalizes HTTP request paths, allowing them to access protected endpoints and potentially steal sensitive data or modify restricted resources without proper authentication.

Technical details

The vulnerability is an authorization bypass in quarkus-vertx-http due to a path normalization discrepancy between the security matcher and HTTP request dispatchers. An unauthenticated attacker can craft a malicious URL that the security matcher treats as a public path (and thus skips authentication checks), but which the underlying HTTP dispatcher routes to a protected endpoint. This allows the attacker to access restricted functionality without credentials. The vulnerability requires only network access and no special authentication or user interaction. A patch is available in Red Hat build of Quarkus 3.33.3.SP2 and later.

Affected products

  • Red Hat Quarkus before 3.33.3.SP2

Timeline

  • 2026-09-18: disclosed
  • 2026-09-21: advisory: RHSA-2026:69440

References