RHSA-2026:7109HighCVSS 8.3

Red Hat Security Advisory: Red Hat build of Quarkus 3.20.6 release and security update

Published
April 14, 2026
Last Modified
May 26, 2026

🔗 CVE IDs covered (5)

CVE-2026-1002 · pendingCVE-2026-33870 · pendingCVE-2026-33871 · pendingCVE-2025-33042 · pendingCVE-2025-67030

📋 Description

CVE-2025-33042 — org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code CVE-2025-67030 — org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood

🔗 References (23)