Red Hat build of Quarkus

6 known vulnerabilities in Red Hat build of Quarkus, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-94449 CVSS 7.5 high A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers…
  • CVE-2026-93432 CVSS 6.1 medium A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the…
  • CVE-2026-10832 CVSS 5.9 medium A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability…
  • CVE-2026-89059 CVSS 7.5 high A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the…
  • CVE-2026-89058 CVSS 7.4 high A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in…
  • CVE-2026-76763 CVSS 7.5 high A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or…