HIGH 7.5 GitHub

CVE-2026-50559

Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. ### Technical Details The security layer (AbstractPathMatchingHttpSecurityPolicy) normalizes request paths using Vert.x's normalizedPath(), which only de

Affected Products

References

Published: 2026-07-29 · Source: GitHub · Feed updated: 2026-08-04
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-07-29 via GitHub. Affected: maven/io.quarkus:quarkus-vertx-http < 3.20.6.2, maven/io.quarkus:quarkus-vertx-http >= 3.21.0.CR1, < 3.27.4.1, maven/io.quarkus:quarkus-vertx-http >= 3.28.0.CR1, < 3.33.2.1 and 2 more.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.