RHSA-2026:62515HighCVSS 8.8

Red Hat Security Advisory: Red Hat build of Quarkus 3.27.5.SP1 release and security update

Published
September 3, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2026-12894 — io.quarkus:quarkus-qute: quarkus-qute:Server-Side Template Injection (SSTI) vulnerability in ReflectionValueResolver of the Quarkus Qute template engine CVE-2026-17615 — resteasy-core: RESTeasy SourceProvider remote unauthenticated file read CVE-2026-18710 — org.mongodb/mongodb-driver: MongoDB Driver: Credential disclosure via cleartext logging during client initialization CVE-2026-19625 — quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache CVE-2026-19651 — quarkus-spring-web: quarkus-spring-web: Authorization bypass via URL query string manipulation CVE-2026-59903 — io.netty/netty: Netty: Information disclosure via CORS Vary header overwrite CVE-2026-62243 — io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration CVE-2026-64607 — org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Denial of Service due to connection leak CVE-2026-66257 — qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching CVE-2026-66273 — org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation CVE-2026-66274 — org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting CVE-2026-71290 — org.apache.httpcomponents.client5/httpclient5: Apache HttpComponents Client: Server impersonation via improper TLS hostname verification CVE-2026-76763 — io.smallrye/smallrye-graphql: SmallRye GraphQL: Unauthenticated Denial of Service via large exponent float literals

🎯 Affected products1

  • Red Hat build of Quarkus 3.27.5.SP1

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Applications utilizing the Quarkus Qute template engine should ensure that untrusted input is not directly incorporated into template content. Restricting access to the application's template rendering functionality to trusted sources can reduce the attack surface. Workaround: To mitigate this issue, avoid exposing RESTEasy endpoints that return Source or StreamSource types. Alternatively, implement a custom MessageBodyWriter for Source types that explicitly applies XML security features to the SAXParserFactory before parsing. Changes to application configuration or code typically require an application redeployment or restart to take effect. Workaround: To mitigate this issue, ensure that access to application logs and any downstream log aggregation storage is strictly controlled. Implement robust access control mechanisms to prevent unauthorized parties from reading log output, as this is where sensitive credentials may be exposed in cleartext during MongoDB driver client initialization. Regularly review and audit log access permissions. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: This vulnerability only affects applications that explicitly configure Netty to use the OpenSSL TLS provider (SslProvider.OPENSSL). The following mitigations can reduce exposure without applying a patch: 1) Use the default JDK SSL provider — Do not configure SslProvider.OPENSSL in your Netty SslContext setup. The default JDK SSL provider (SslProvider.JDK) is not affected by this vulnerability. Most applications use the JDK default unless explicitly overridden. 2) Use X509ExtendedTrustManager — If the OpenSSL provider is required, ensure the configured trust manager extends X509ExtendedTrustManager rather than the plain X509TrustManager interface. The extended variant performs hostname verification independently of the Netty wrapping logic. 3) Run on Java 24 or earlier — The vulnerable code path only triggers on Java 25+ where sun.misc.Unsafe-based trust-manager wrapping is unavailable. Running on earlier Java versions (e.g., Java 21 LTS) means the wrapping works correctly and hostname verification stays enabled. Workaround: To mitigate this issue, restrict network access to services utilizing Apache Qpid Proton-J to trusted clients and networks only. Implement firewall rules to limit inbound connections to the specific ports used by these services. This operational control reduces the attack surface by preventing untrusted external access, but may impact legitimate client connectivity if not carefully configured. Workaround: To mitigate this issue, applications exposing SmallRye GraphQL endpoints should implement validation and bounding of the precision or exponent for incoming numeric literals before they reach scalar coercion. Additionally, limiting the JVM heap size can help constrain the impact of OutOfMemoryError, though it will not prevent CPU exhaustion. Implementing rate-limiting or timeouts on the GraphQL endpoint can also reduce exposure. Using GraphQL variables instead of inline literals for numeric inputs is a safe alternative, as variables follow a secure parsing path.

🔗 References (6)