Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.1%top 96%

Red Hat Security Advisory: Red Hat build of Quarkus 3.33.2.SP3 security update

0
High
Published: 07/30/2026 (07/30/2026, 01:40:45 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This release of Red Hat build of Quarkus 3.33.2.SP3 includes the following CVE fixes: * resteasy-reactive-client-processor: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service [quarkus-3.33] (CVE-2026-16308) * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [quarkus-3.33] (CVE-2026-15075) * httpcore: org.apache.httpcomponents.core5:httpcore5: Denial of Service via excessive HTTP headers [quarkus-3.33] (CVE-2026-54399) * org.apache.httpcomponents.core5:httpcore5-h2:HPackDecoder Unlimited Header List Size Before SETTINGS ACK [quarkus-3.33] (CVE-2026-54428) * vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation [quarkus-3.33] (CVE-2026-15076) * netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [quarkus-3.33] (CVE-2026-55833) * netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [quarkus-3.33] (CVE-2026-55831) * netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [quarkus-3.33] (CVE-2026-55851) * netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [quarkus-3.33] (CVE-2026-56745) * netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [quarkus-3.33] (CVE-2026-56746) * netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [quarkus-3.33] (CVE-2026-56819) * netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [quarkus-3.33] (CVE-2026-59899) * netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder [quarkus-3.33] (CVE-2026-59921) * netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 [quarkus-3.33] (CVE-2026-59900) * netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) [quarkus-3.33] (CVE-2026-59898) For more information, see the release notes page listed in the References section.

Affected software

Affected versions
Red HatRed Hat build of QuarkusRed Hat build of Quarkus 3.33.2.SP3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 07:10:07 UTC

Technical Analysis

This Red Hat security advisory covers a set of 13 CVEs fixed in Red Hat build of Quarkus 3.27.4.SP3. Vulnerabilities include denial of service attacks caused by unbounded multipart MIME header accumulation, SPDY header decompression amplification, memory exhaustion in HTTP/2 and SPDY codecs, and crafted PROXY protocol messages. Information disclosure issues arise from improper handling of HTTP 30x redirects and cookie domain validation in Eclipse Vert.x components. Additional issues include security control bypass via null origin headers, CRLF injection through multipart filenames, improper header neutralization in HTTP/2, and protocol version confusion in WebSocket handling. The advisory references Red Hat errata RHSA-2026:47189 for detailed remediation instructions.

Potential Impact

The vulnerabilities collectively allow remote attackers to cause denial of service conditions through memory exhaustion or amplification attacks, potentially leading to application crashes or resource depletion. Information disclosure flaws may expose sensitive data via improper HTTP redirect handling and cookie validation. Security control bypass and injection vulnerabilities could allow unauthorized requests or manipulation of HTTP headers. These issues affect the stability, confidentiality, and integrity of applications using the affected Quarkus components and underlying Netty libraries.

Mitigation Recommendations

Red Hat has released an official security update in Red Hat build of Quarkus 3.27.4.SP3 that addresses all listed vulnerabilities. Users should apply this update promptly after ensuring all previously released relevant errata are installed. Detailed update instructions are available in the Red Hat advisory RHSA-2026:47189 and associated documentation. No additional mitigations are specified beyond applying the official patch.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:47189
Cve Count
13
Additional Cves
["CVE-2026-15076","CVE-2026-16308","CVE-2026-55831","CVE-2026-55833","CVE-2026-55851","CVE-2026-56745","CVE-2026-56746","CVE-2026-56819","CVE-2026-59898","CVE-2026-59899","CVE-2026-59900","CVE-2026-59921"]
Cvss Version
null

Threat ID: 6a6ae5429c2644c7f8987aaa

Added to database: 07/30/2026, 05:46:42 UTC

Last enriched: 07/30/2026, 07:10:07 UTC

Last updated: 07/31/2026, 01:00:15 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses