Bug 2536859 (CVE-2026-93432)

Summary: CVE-2026-93432 io.quarkus.qute:quarkus-core: Cross-Site Scripting (XSS) and JSON Injection via Qute {#eval} Section in Quarkus
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ant, aschwart, aszczucz, boliveir, cescoffi, cmah, drichtar, ewittman, fmongiar, gmalinko, gsmet, janstey, jmartisk, jnethert, kaycoth, manderse, mposolda, nipatil, olubyans, ozzy, pantinor, pdelbell, pjindal, rguimara, rkubis, rmartinc, rstepani, sbiarozk, ssilvert, sthorger, varjain, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-17 21:43:58 UTC
A vulnerability in the Quarkus Qute template engine leads to improper output escaping when using the {#eval} section helper.
When EvalSectionHelper parses a sub-template, it fails to pass the parent template's Variant (which dictates the content type, such as HTML or JSON). Because Qute's standard escapers (HtmlEscaper, JsonEscaper) require this variant to determine if and how escaping should be applied, they silently bypass the evaluated content. As a result, any untrusted data processed inside an {#eval} block is output as raw, unescaped text.