CVE-2026-39852Disclosure(quarkus / quarkus)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch quarkus quarkus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Quarkus's security layer performs authorization checks on the raw URL path which preserves matrix parameters (semicolons), while RESTEasy Reactive's routing layer strips matrix parameters before matching endpoints. An attacker can append a semicolon and arbitrary text to a request URL (e.g., /api/admin;anything) to bypass policies protecting /api/admin while still routing to the protected endpoint. This issue has been fixed in versions 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-551

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • quarkus

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-05); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
quarkus

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-04: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-26: 105-0405-0505-0605-26
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-041
Patch1
2026-05-052
Disclosure2
2026-05-061
General1
2026-05-261
General1
Full discourse5 posts
  • Elder Moraes@elderjava
    General

    A request to /api/admin gets blocked. A request to /api/admin;anything goes through. Same endpoint, same handler, same data. That's CVE-2026-39852 in Quarkus. The architecture under it is more interesting than the bug itself. 1/7

    Post summary

    The tweet highlights a routing/authorization bug in Quarkus (CVE-2026-39852) where a semicolon bypasses access control, but does not provide a PoC, exploit tool, patch, or evidence of active exploitation.

    10020421
    7.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39852 Path Normalization Bypass in Quarkus HTTP Authorization Prior to 3.35.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39852

    Post summary

    A path normalization bypass vulnerability exists in Quarkus HTTP Authorization before version 3.35.2; no PoC, exploit, or patch details are provided.

    0000054
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39852 Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalizat… https://www.cve.org/CVERecord?id=CVE-2026-39852 ----- Traducción: CVE-2026-39852 Qua… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-39852, a path normalization issue affecting specific Quarkus versions, and links to the official CVE record.

    0000028
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39852 Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalizat… https://www.cve.org/CVERecord?id=CVE-2026-39852

    Post summary

    The text provides a brief disclosure of a path normalization vulnerability in Quarkus, noting the affected versions, with no mention of exploits, patches, or active attacks.

    00000186
    57.4K followersView on X
  • daily.dev@dailydotdev
    Patch

    MAJOR: Quarkus patches severe CVE-2026-39852 across all supported streams

    Post summary

    Quarkus has released patches covering all supported streams for the severe CVE-2026-39852.

    00000261
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appquarkusquarkus---

Explore more