Bug 2530523 (CVE-2026-87743) - CVE-2026-87743 quarkus-vertx-http: Authorization Bypass via Path Normalization Discrepancy in Quarkus HTTP Security
Summary: CVE-2026-87743 quarkus-vertx-http: Authorization Bypass via Path Normalizatio...
Keywords:
Status: NEW
Alias: CVE-2026-87743
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-09 06:13 UTC by OSIDB Bzimport
Modified: 2026-09-17 13:24 UTC (History)
56 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-09 06:13:15 UTC
Title: Authorization Bypass via Path Normalization Discrepancy in Quarkus HTTP Security
Summary: 

A vulnerability in the Quarkus HTTP security matcher allows unauthenticated attackers to bypass path-based access control rules. Because paths are normalized differently between the security matcher and the HTTP request dispatchers (e.g., RESTEasy, Undertow), an attacker can craft a URL that the security matcher treats as public, but the router dispatches to a protected endpoint.This issue is an incomplete fix for CVE-2026-50559.
Component: io.quarkus:quarkus-vertx-http
CWE: CWE-285, CWE-288, CWE-436
Scoring: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5/10)
Affected versions: 3.27, 3.33

Credit: Michael Read (https://github.com/Michael-JRead)


Note You need to log in before you can comment on or make changes to this bug.