CVE-2026-93579
- EPSS 0.23%
- Veröffentlicht 18.09.2026 16:38:29
- Zuletzt bearbeitet 29.09.2026 19:17:27
A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cros...
CVE-2026-93567
- EPSS 0.4%
- Veröffentlicht 18.09.2026 14:23:27
- Zuletzt bearbeitet 22.09.2026 19:16:58
A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit t...
CVE-2023-6394
- EPSS 0.81%
- Veröffentlicht 09.12.2023 02:15:06
- Zuletzt bearbeitet 29.09.2026 10:17:10
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can...
CVE-2023-6393
- EPSS 0.63%
- Veröffentlicht 06.12.2023 17:15:07
- Zuletzt bearbeitet 29.09.2026 10:17:08
A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This...
CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-4853
- EPSS 1.22%
- Veröffentlicht 20.09.2023 10:15:14
- Zuletzt bearbeitet 04.08.2026 18:16:39
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security ...
CVE-2023-1108
- EPSS 1.77%
- Veröffentlicht 14.09.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:38:28
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
CVE-2023-2974
- EPSS 0.88%
- Veröffentlicht 04.07.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:40
A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force the selection of the weaker supported TLS protocol.
CVE-2023-1664
- EPSS 0.43%
- Veröffentlicht 26.05.2023 18:15:09
- Zuletzt bearbeitet 15.01.2025 22:15:25
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certifi...
CVE-2023-0044
- EPSS 0.55%
- Veröffentlicht 23.02.2023 20:15:12
- Zuletzt bearbeitet 21.11.2024 07:36:27
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.