Red Hat Security Advisory: Red Hat build of Quarkus 3.33.2.SP2 security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-9800 — keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison CVE-2026-40983 — micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests CVE-2026-40984 — micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution CVE-2026-54514 — jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution CVE-2026-54515 — jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified CVE-2026-54516 — jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties CVE-2026-54517 — jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application CVE-2026-54518 — jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass
🎯 Affected products1
- Red Hat build of Quarkus 3.33.2.SP2
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services exposing Micrometer's gRPC endpoints to trusted clients only. Implement firewall rules to limit inbound connections to the specific ports used by gRPC. If gRPC functionality is not essential for the deployment, consider disabling it entirely to eliminate the attack vector. Any changes to network configurations or service settings may require a service restart to take effect, potentially impacting availability during the transition. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:36013
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/products/quarkus/
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.33.2.SP2
- externalhttps://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.33
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36013.json