CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Quarkus Redhat2Build Of Quarkus QuarkusMar 24, 2026 Dec 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the en...Show more |
A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instea...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreMay 12, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
2Quarkus Redhat12Build Of Optaplanner Build Of QuarkusDecision Manager+9 moreNov 21, 2024 Sep 20, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an at...Show more |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreNov 21, 2024 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS...Show more |
1Redhat 5Build Of Quarkus Jboss A MqKeycloak+2 moreJan 15, 2025 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an a...Show more |
2Quarkus Redhat2Build Of Quarkus QuarkusNov 21, 2024 Feb 23, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF...Show more |
1Redhat 10Build Of Quarkus Integration Camel For Spring BootIntegration Camel K+7 moreMar 12, 2025 Feb 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add...Show more |
2Quarkus Redhat2Build Of Quarkus QuarkusApr 29, 2025 Nov 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution. |
2Netapp Redhat10Active Iq Unified Manager Build Of QuarkusCloud Secure Agent+7 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-...Show more |
5Debian FedoraprojectIbm+2 more23Build Of Quarkus Codeready Linux BuilderDebian Linux+20 moreNov 3, 2025 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. |
1Redhat 3Build Of Quarkus Openshift Application RuntimesSmallrye HealthNov 21, 2024 Aug 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks. |
1Redhat 9A Mq Streams Build Of QuarkusDescision Manager+6 moreNov 21, 2024 Aug 24, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supp...Show more |
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreNov 21, 2024 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
5Debian FedoraprojectLinux+2 more23Build Of Quarkus Codeready Linux BuilderCodeready Linux Builder Eus+20 moreNov 21, 2024 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is simi...Show more |
3Linux NetappRedhat323scale Api Management Build Of QuarkusCodeready Linux Builder Eus+29 moreNov 21, 2024 Mar 3, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in ne...Show more |
2Quarkus Redhat13Build Of Quarkus Codeready StudioData Grid+10 moreNov 21, 2024 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnera...Show more |
1Redhat 9Build Of Quarkus Data GridDescision Manager+6 moreNov 21, 2024 May 20, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality...Show more |
1Redhat 9A Mq Online Build Of QuarkusCodeready Studio+6 moreNov 21, 2024 Mar 16, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside t...Show more |