RHSA-2026:7109HighCVSS 8.3
Red Hat Security Advisory: Red Hat build of Quarkus 3.20.6 release and security update
🔗 CVE IDs covered (5)
CVE-2026-1002 · pendingCVE-2026-33870 · pendingCVE-2026-33871 · pendingCVE-2025-33042 · pendingCVE-2025-67030 →
📋 Description
CVE-2025-33042 — org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code CVE-2025-67030 — org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2026:7109
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/products/quarkus/
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.20.6
- externalhttps://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.20
- externalhttps://issues.redhat.com/browse/QUARKUS-6878
- externalhttps://issues.redhat.com/browse/QUARKUS-7203
- externalhttps://issues.redhat.com/browse/QUARKUS-7204
- externalhttps://issues.redhat.com/browse/QUARKUS-7206
- externalhttps://issues.redhat.com/browse/QUARKUS-7207
- externalhttps://issues.redhat.com/browse/QUARKUS-7322
- externalhttps://issues.redhat.com/browse/QUARKUS-7323
- externalhttps://issues.redhat.com/browse/QUARKUS-7324
- externalhttps://issues.redhat.com/browse/QUARKUS-7325
- externalhttps://issues.redhat.com/browse/QUARKUS-7326
- externalhttps://issues.redhat.com/browse/QUARKUS-7327
- externalhttps://issues.redhat.com/browse/QUARKUS-7328
- externalhttps://issues.redhat.com/browse/QUARKUS-7329
- externalhttps://issues.redhat.com/browse/QUARKUS-7330
- externalhttps://issues.redhat.com/browse/QUARKUS-7331
- externalhttps://issues.redhat.com/browse/QUARKUS-7347
- externalhttps://issues.redhat.com/browse/QUARKUS-7379
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7109.json