REDHAT-BUG-2530523: High severity Quarkus io.quarkus:quarkus-vertx-http vulnerability

Published Sep 9, 2026
·
Updated

Title: Authorization Bypass via Path Normalization Discrepancy in Quarkus HTTP Security Summary:

A vulnerability in the Quarkus HTTP security matcher allows unauthenticated attackers to bypass path-based access control rules. Because paths are normalized differently between the security matcher and the HTTP request dispatchers (e.g., RESTEasy, Undertow), an attacker can craft a URL that the security matcher treats as public, but the router dispatches to a protected endpoint.This issue is an incomplete fix for CVE-2026-50559. Component: io.quarkus:quarkus-vertx-http CWE: CWE-285, CWE-288, CWE-436 Scoring: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5/10) Affected versions: 3.27, 3.33

Credit: Michael Read (https://github.com/Michael-JRead)

Affected Software

1 affected component
Quarkus io.quarkus:quarkus-vertx-http>=3.27<=3.33

Event History

Sep 9, 2026
Data Sourced
via Red Hat·06:13 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using the Quarkus HTTP security matcher with path-based access-control rules are exposed if their request dispatcher normalizes paths differently. The affected component is io.quarkus:quarkus-vertx-http, with affected versions listed as 3.27 and 3.33.

2

What does an attacker need to exploit the bypass?

An attacker can be unauthenticated and can exploit the issue remotely with low attack complexity. They need to craft a URL whose path is treated as public by the security matcher but is dispatched by the HTTP router to a protected endpoint.

3

What is the likely impact if exploitation succeeds?

The bypass can expose protected endpoints to unauthorized access. The supplied CVSS vector indicates high confidentiality impact, with no indicated integrity or availability impact.

4

How can I determine whether my application is affected?

Review whether the application uses Quarkus HTTP path-based security rules and whether protected routes are dispatched through RESTEasy, Undertow, or another dispatcher with different path normalization behavior. Versions 3.27 and 3.33 are identified as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203