Red Hat Security Advisory: Red Hat build of Quarkus 3.20.3 release and security update
This release of Red Hat build of Quarkus 3.20.3 includes the following CVE fixes: * netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions [quarkus-3.20] (CVE-2025-58056) * netty-codec: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack [quarkus-3.20] (CVE-2025-58057) For more information, see the release notes page listed in the References section.
AI Analysis
Technical Summary
This advisory covers two vulnerabilities fixed in Red Hat build of Quarkus 3.20.3. CVE-2025-58056 is a request smuggling vulnerability in Netty's HTTP/2 and HTTP codec modules caused by incorrect parsing of chunk extensions. CVE-2025-58057 is a denial-of-service vulnerability in Netty's BrotliDecoder due to zip bomb style attacks. The update includes these fixes and other component version bumps to improve security and stability. Red Hat rates the security impact as moderate and recommends applying the update after ensuring all prior errata are applied.
Potential Impact
Successful exploitation of CVE-2025-58056 could allow an attacker to perform HTTP request smuggling attacks, potentially bypassing security controls or interfering with HTTP traffic processing. CVE-2025-58057 could allow denial-of-service conditions via specially crafted compressed data causing resource exhaustion. Both vulnerabilities affect the underlying Netty components used in the Red Hat build of Quarkus 3.20.3, impacting applications relying on this runtime. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A security update for Red Hat build of Quarkus 3.20.3 is available that addresses these vulnerabilities. Red Hat advises applying this update after ensuring all previously released errata relevant to your system have been applied. Detailed update instructions are available in the Red Hat advisory RHSA-2025:17563 and related documentation. No alternative mitigations or workarounds are specified.
Red Hat Security Advisory: Red Hat build of Quarkus 3.20.3 release and security update
Description
This release of Red Hat build of Quarkus 3.20.3 includes the following CVE fixes: * netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions [quarkus-3.20] (CVE-2025-58056) * netty-codec: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack [quarkus-3.20] (CVE-2025-58057) For more information, see the release notes page listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers two vulnerabilities fixed in Red Hat build of Quarkus 3.20.3. CVE-2025-58056 is a request smuggling vulnerability in Netty's HTTP/2 and HTTP codec modules caused by incorrect parsing of chunk extensions. CVE-2025-58057 is a denial-of-service vulnerability in Netty's BrotliDecoder due to zip bomb style attacks. The update includes these fixes and other component version bumps to improve security and stability. Red Hat rates the security impact as moderate and recommends applying the update after ensuring all prior errata are applied.
Potential Impact
Successful exploitation of CVE-2025-58056 could allow an attacker to perform HTTP request smuggling attacks, potentially bypassing security controls or interfering with HTTP traffic processing. CVE-2025-58057 could allow denial-of-service conditions via specially crafted compressed data causing resource exhaustion. Both vulnerabilities affect the underlying Netty components used in the Red Hat build of Quarkus 3.20.3, impacting applications relying on this runtime. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A security update for Red Hat build of Quarkus 3.20.3 is available that addresses these vulnerabilities. Red Hat advises applying this update after ensuring all previously released errata relevant to your system have been applied. Detailed update instructions are available in the Red Hat advisory RHSA-2025:17563 and related documentation. No alternative mitigations or workarounds are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:17563
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-58057"]
Threat ID: 6a3c0cf0eed863c81e238cc0
Added to database: 06/24/2026, 16:59:28 UTC
Last enriched: 07/03/2026, 01:07:53 UTC
Last updated: 09/10/2026, 19:24:57 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.