Fedora Account System
Red Hat Associate
Red Hat Customer
Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static.
This issue has been addressed in the following products: Red Hat build of Quarkus 3.27.4.SP1 Via RHSA-2026:26018 https://access.redhat.com/errata/RHSA-2026:26018
This issue has been addressed in the following products: Red Hat build of Quarkus 3.20.6.SP2 Via RHSA-2026:26194 https://access.redhat.com/errata/RHSA-2026:26194
This issue has been addressed in the following products: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 Via RHSA-2026:26586 https://access.redhat.com/errata/RHSA-2026:26586
This issue has been addressed in the following products: Streams for Apache Kafka 2.9.4 Via RHSA-2026:34608 https://access.redhat.com/errata/RHSA-2026:34608
This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151