REDHAT-BUG-2530523: High severity Quarkus io.quarkus:quarkus-vertx-http vulnerability
Title: Authorization Bypass via Path Normalization Discrepancy in Quarkus HTTP Security Summary:
A vulnerability in the Quarkus HTTP security matcher allows unauthenticated attackers to bypass path-based access control rules. Because paths are normalized differently between the security matcher and the HTTP request dispatchers (e.g., RESTEasy, Undertow), an attacker can craft a URL that the security matcher treats as public, but the router dispatches to a protected endpoint.This issue is an incomplete fix for CVE-2026-50559. Component: io.quarkus:quarkus-vertx-http CWE: CWE-285, CWE-288, CWE-436 Scoring: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5/10) Affected versions: 3.27, 3.33
Credit: Michael Read (https://github.com/Michael-JRead)
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using the Quarkus HTTP security matcher with path-based access-control rules are exposed if their request dispatcher normalizes paths differently. The affected component is io.quarkus:quarkus-vertx-http, with affected versions listed as 3.27 and 3.33.
What does an attacker need to exploit the bypass?
An attacker can be unauthenticated and can exploit the issue remotely with low attack complexity. They need to craft a URL whose path is treated as public by the security matcher but is dispatched by the HTTP router to a protected endpoint.
What is the likely impact if exploitation succeeds?
The bypass can expose protected endpoints to unauthorized access. The supplied CVSS vector indicates high confidentiality impact, with no indicated integrity or availability impact.
How can I determine whether my application is affected?
Review whether the application uses Quarkus HTTP path-based security rules and whether protected routes are dispatched through RESTEasy, Undertow, or another dispatcher with different path normalization behavior. Versions 3.27 and 3.33 are identified as affected.