Red Hat Security Advisory: Red Hat build of Quarkus 3.33.2.SP3 security update
This release of Red Hat build of Quarkus 3.33.2.SP3 includes the following CVE fixes: * resteasy-reactive-client-processor: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service [quarkus-3.33] (CVE-2026-16308) * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [quarkus-3.33] (CVE-2026-15075) * httpcore: org.apache.httpcomponents.core5:httpcore5: Denial of Service via excessive HTTP headers [quarkus-3.33] (CVE-2026-54399) * org.apache.httpcomponents.core5:httpcore5-h2:HPackDecoder Unlimited Header List Size Before SETTINGS ACK [quarkus-3.33] (CVE-2026-54428) * vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation [quarkus-3.33] (CVE-2026-15076) * netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [quarkus-3.33] (CVE-2026-55833) * netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [quarkus-3.33] (CVE-2026-55831) * netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [quarkus-3.33] (CVE-2026-55851) * netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [quarkus-3.33] (CVE-2026-56745) * netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [quarkus-3.33] (CVE-2026-56746) * netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [quarkus-3.33] (CVE-2026-56819) * netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [quarkus-3.33] (CVE-2026-59899) * netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder [quarkus-3.33] (CVE-2026-59921) * netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 [quarkus-3.33] (CVE-2026-59900) * netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) [quarkus-3.33] (CVE-2026-59898) For more information, see the release notes page listed in the References section.
AI Analysis
Technical Summary
This Red Hat security advisory covers a set of 13 CVEs fixed in Red Hat build of Quarkus 3.27.4.SP3. Vulnerabilities include denial of service attacks caused by unbounded multipart MIME header accumulation, SPDY header decompression amplification, memory exhaustion in HTTP/2 and SPDY codecs, and crafted PROXY protocol messages. Information disclosure issues arise from improper handling of HTTP 30x redirects and cookie domain validation in Eclipse Vert.x components. Additional issues include security control bypass via null origin headers, CRLF injection through multipart filenames, improper header neutralization in HTTP/2, and protocol version confusion in WebSocket handling. The advisory references Red Hat errata RHSA-2026:47189 for detailed remediation instructions.
Potential Impact
The vulnerabilities collectively allow remote attackers to cause denial of service conditions through memory exhaustion or amplification attacks, potentially leading to application crashes or resource depletion. Information disclosure flaws may expose sensitive data via improper HTTP redirect handling and cookie validation. Security control bypass and injection vulnerabilities could allow unauthorized requests or manipulation of HTTP headers. These issues affect the stability, confidentiality, and integrity of applications using the affected Quarkus components and underlying Netty libraries.
Mitigation Recommendations
Red Hat has released an official security update in Red Hat build of Quarkus 3.27.4.SP3 that addresses all listed vulnerabilities. Users should apply this update promptly after ensuring all previously released relevant errata are installed. Detailed update instructions are available in the Red Hat advisory RHSA-2026:47189 and associated documentation. No additional mitigations are specified beyond applying the official patch.
Red Hat Security Advisory: Red Hat build of Quarkus 3.33.2.SP3 security update
Description
This release of Red Hat build of Quarkus 3.33.2.SP3 includes the following CVE fixes: * resteasy-reactive-client-processor: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service [quarkus-3.33] (CVE-2026-16308) * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects [quarkus-3.33] (CVE-2026-15075) * httpcore: org.apache.httpcomponents.core5:httpcore5: Denial of Service via excessive HTTP headers [quarkus-3.33] (CVE-2026-54399) * org.apache.httpcomponents.core5:httpcore5-h2:HPackDecoder Unlimited Header List Size Before SETTINGS ACK [quarkus-3.33] (CVE-2026-54428) * vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation [quarkus-3.33] (CVE-2026-15076) * netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [quarkus-3.33] (CVE-2026-55833) * netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [quarkus-3.33] (CVE-2026-55831) * netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [quarkus-3.33] (CVE-2026-55851) * netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [quarkus-3.33] (CVE-2026-56745) * netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [quarkus-3.33] (CVE-2026-56746) * netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [quarkus-3.33] (CVE-2026-56819) * netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [quarkus-3.33] (CVE-2026-59899) * netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder [quarkus-3.33] (CVE-2026-59921) * netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 [quarkus-3.33] (CVE-2026-59900) * netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket) [quarkus-3.33] (CVE-2026-59898) For more information, see the release notes page listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory covers a set of 13 CVEs fixed in Red Hat build of Quarkus 3.27.4.SP3. Vulnerabilities include denial of service attacks caused by unbounded multipart MIME header accumulation, SPDY header decompression amplification, memory exhaustion in HTTP/2 and SPDY codecs, and crafted PROXY protocol messages. Information disclosure issues arise from improper handling of HTTP 30x redirects and cookie domain validation in Eclipse Vert.x components. Additional issues include security control bypass via null origin headers, CRLF injection through multipart filenames, improper header neutralization in HTTP/2, and protocol version confusion in WebSocket handling. The advisory references Red Hat errata RHSA-2026:47189 for detailed remediation instructions.
Potential Impact
The vulnerabilities collectively allow remote attackers to cause denial of service conditions through memory exhaustion or amplification attacks, potentially leading to application crashes or resource depletion. Information disclosure flaws may expose sensitive data via improper HTTP redirect handling and cookie validation. Security control bypass and injection vulnerabilities could allow unauthorized requests or manipulation of HTTP headers. These issues affect the stability, confidentiality, and integrity of applications using the affected Quarkus components and underlying Netty libraries.
Mitigation Recommendations
Red Hat has released an official security update in Red Hat build of Quarkus 3.27.4.SP3 that addresses all listed vulnerabilities. Users should apply this update promptly after ensuring all previously released relevant errata are installed. Detailed update instructions are available in the Red Hat advisory RHSA-2026:47189 and associated documentation. No additional mitigations are specified beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:47189
- Cve Count
- 13
- Additional Cves
- ["CVE-2026-15076","CVE-2026-16308","CVE-2026-55831","CVE-2026-55833","CVE-2026-55851","CVE-2026-56745","CVE-2026-56746","CVE-2026-56819","CVE-2026-59898","CVE-2026-59899","CVE-2026-59900","CVE-2026-59921"]
- Cvss Version
- null
Threat ID: 6a6ae5429c2644c7f8987aaa
Added to database: 07/30/2026, 05:46:42 UTC
Last enriched: 07/30/2026, 07:10:07 UTC
Last updated: 07/31/2026, 01:00:15 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.