RHSA-2025:0900: Moderate: Red Hat build of Quarkus 3.15.3 release and security update
Moderate: Red Hat build of Quarkus 3.15.3 release and security update
Other sources
This release of Red Hat build of Quarkus 3.15.3 includes the following CVE fixes:<br><li> io.quarkus/quarkus-netty: Denial of Service attack on windows app using Netty [quarkus-3.15] (CVE-2024-47535)</li> <li> io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling [quarkus-3.15] (CVE-2024-12397)</li>
For more information, see the release notes page listed in the References<br>section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0900?
RHSA-2025:0900 is categorized as a moderate severity vulnerability affecting the Red Hat build of Quarkus.
How do I fix RHSA-2025:0900?
To fix RHSA-2025:0900, update your Red Hat build of Quarkus to the latest version 3.15.3.
What vulnerabilities are addressed in RHSA-2025:0900?
RHSA-2025:0900 addresses the denial of service vulnerability in io.quarkus/quarkus-netty from CVE-2024-47535.
Which products are affected by RHSA-2025:0900?
RHSA-2025:0900 affects the Red Hat build of Quarkus, specifically version 3.15.3.
Is there any known exploit for RHSA-2025:0900?
Currently, there are no public exploits known for the vulnerabilities addressed in RHSA-2025:0900.