CVE-2026-50559Patch(quarkus / quarkus)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch quarkus quarkus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-863CWE-551

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • quarkus

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
quarkus

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-19: 2Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-19: 106-1906-22
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-192
Disclosure1Patch1
2026-06-221
Patch1
Full discourse3 posts
  • Munshipremchand@MunshiPremChnd
    Patch

    Excited to share this week’s Java News Roundup! Get the latest on point releases for Spring Tools, Helidon, JobRunr, and Gradle, June 2026 Open Liberty, Apache TomEE 11.0 milestone, Hibernate ORM 8.0 beta, Quarkus emergency fixes for CVE-2026-50559, and … https://ift.tt/9IeRfSu

    Post summary

    The post lists Java releases and highlights that Quarkus has issued emergency fixes for CVE-2026-50559, indicating a patch is available.

    0000048
    339 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50559 Quarkus versions prior to 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 permit attackers to circumvent HTTP path-based authorization policies through two distinct methods https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50559

    Post summary

    The advisory notes that certain Quarkus versions allow attackers to bypass HTTP path-based authorization policies, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000045
    4.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-50559 Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP p… https://www.cve.org/CVERecord?id=CVE-2026-50559

    Post summary

    CVE‑2026‑50559 lists older Quarkus releases as vulnerable and indicates that newer versions provide a fix.

    00000209
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appquarkusquarkus---

Explore more