RHSA-2025:0900MediumCVSS 7.4

Red Hat Security Advisory: Red Hat build of Quarkus 3.15.3 release and security update

Published
February 5, 2025
Last Modified
July 30, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-12397 — io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling CVE-2024-47535 — netty: Denial of Service attack on windows app using Netty

🎯 Affected products1

  • Red Hat build of Quarkus 3.15.3

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Currently, no mitigation is available for this vulnerability.

🔗 References (35)