Elder Moraes[verified]@elderjavaGeneral
The tweet highlights a routing/authorization bug in Quarkus (CVE-2026-39852) where a semicolon bypasses access control, but does not provide a PoC, exploit tool, patch, or evidence of active exploitation.
daily.dev[verified]@dailydotdevPatch
Quarkus has released patches covering all supported streams for the severe CVE-2026-39852.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
A path normalization bypass vulnerability exists in Quarkus HTTP Authorization before version 3.35.2; no PoC, exploit, or patch details are provided.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE-2026-39852, a path normalization issue affecting specific Quarkus versions, and links to the official CVE record.
CVE@CVEnewDisclosure
The text provides a brief disclosure of a path normalization vulnerability in Quarkus, noting the affected versions, with no mention of exploits, patches, or active attacks.