RHSA-2026:53643: Important: Red Hat build of Quarkus 3.27.5 release and security update
Important: Red Hat build of Quarkus 3.27.5 release and security update
Other sources
This release of Red Hat build of Quarkus 3.27.5 includes the following CVE fixes: scram-common: SCRAM Libraries: Authentication downgrade via TLS man-in-the-middle attack [quarkus-3.27] (CVE-2026-53712) jansi: Jansi: Heap buffer overflow leads to Denial of Service [quarkus-3.27] (CVE-2026-8484) postgresql: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade [quarkus-3.27] (CVE-2026-54291) sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation [quarkus-3.27] (CVE-2026-56624)For more information, see the release notes page listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
quarkus-3.27.5to a version that resolves this vulnerability.Fixed in 3.27.5 - Upgrade
Upgrade
quarkus 3.27.5 - jansito a version that resolves this vulnerability.Patch CVE-2026-8484 - Upgrade
Upgrade
quarkus 3.27.5 - pgjdbcto a version that resolves this vulnerability.Patch CVE-2026-54291 - Upgrade
Upgrade
quarkus 3.27.5 - sshd-core (Apache MINA SSHD)to a version that resolves this vulnerability.Patch CVE-2026-56624 - Upgrade
Upgrade
quarkus 3.27.5 - scram-commonto a version that resolves this vulnerability.Patch CVE-2026-53712
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:53643?
The severity of RHSA-2026:53643 is high, rated at 7.
What vulnerabilities are addressed in RHSA-2026:53643?
RHSA-2026:53643 addresses vulnerabilities including CVE-2026-53712 related to authentication downgrades via a TLS man-in-the-middle attack.
How do I fix RHSA-2026:53643?
To fix RHSA-2026:53643, update to the latest Red Hat build of Quarkus 3.27.5.
What types of vulnerabilities does RHSA-2026:53643 include?
RHSA-2026:53643 includes vulnerabilities related to buffer overflow and authentication issues.
Why is it important to apply the update from RHSA-2026:53643?
Applying the update from RHSA-2026:53643 is important to mitigate security risks associated with authentication downgrades and potential exploit scenarios.