RHSA-2026:51653: Important: Red Hat build of Quarkus 3.33.3 release and security update
Important: Red Hat build of Quarkus 3.33.3 release and security update
Other sources
This release of Red Hat build of Quarkus 3.33.3 includes the following CVE fixes: scram-common: SCRAM Libraries: Authentication downgrade via TLS man-in-the-middle attack [quarkus-3.33] (CVE-2026-53712) jansi: Jansi: Heap buffer overflow leads to Denial of Service [quarkus-3.33] (CVE-2026-8484) postgresql: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade [quarkus-3.33] (CVE-2026-54291) sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation [quarkus-3.33] (CVE-2026-56624) For more information, see the release notes page listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
jansito a version that resolves this vulnerability.Fixed in 3.33.3 - Upgrade
Upgrade
postgresql/pgjdbcto a version that resolves this vulnerability.Fixed in 3.33.3Patch CVE-2026-54291 - Upgrade
Upgrade
sshd-core/Apache MINA SSHDto a version that resolves this vulnerability.Fixed in 3.33.3Patch CVE-2026-56624 - Upgrade
Upgrade
scram-common/SCRAM Librariesto a version that resolves this vulnerability.Fixed in 3.33.3Patch CVE-2026-53712 - Compensating control
Before applying this update, make sure all previously released errata relevant to your system have been applied.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:51653?
The severity of RHSA-2026:51653 is classified as high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:51653?
RHSA-2026:51653 addresses vulnerabilities including CVE-2026-53712 related to authentication downgrade via TLS man-in-the-middle attack and buffer overflow issues.
How do I fix RHSA-2026:51653?
To fix RHSA-2026:51653, update to the latest release of Red Hat build of Quarkus 3.33.3.
What software does RHSA-2026:51653 affect?
RHSA-2026:51653 affects the Red Hat build of Quarkus.
When was RHSA-2026:51653 published?
RHSA-2026:51653 was published on August 13, 2026.