RHSA-2026:7380HighCVSS 8.3
Red Hat Security Advisory: Red Hat build of Quarkus 3.27.3 release and security update
🔗 CVE IDs covered (5)
CVE-2025-33042 · pendingCVE-2025-67030 →CVE-2026-1002 · pendingCVE-2026-33870 · pendingCVE-2026-33871 · pending
📋 Description
CVE-2025-33042 — org.apache.avro/avro: Apache Avro Java SDK: Code injection on Java generated code CVE-2025-67030 — org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
🔗 References (51)
- selfhttps://access.redhat.com/errata/RHSA-2026:7380
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/products/quarkus/
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.27.3
- externalhttps://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.27
- externalhttps://issues.redhat.com/browse/QUARKUS-5216
- externalhttps://issues.redhat.com/browse/QUARKUS-6747
- externalhttps://issues.redhat.com/browse/QUARKUS-6945
- externalhttps://issues.redhat.com/browse/QUARKUS-6947
- externalhttps://issues.redhat.com/browse/QUARKUS-6953
- externalhttps://issues.redhat.com/browse/QUARKUS-6954
- externalhttps://issues.redhat.com/browse/QUARKUS-7125
- externalhttps://issues.redhat.com/browse/QUARKUS-7130
- externalhttps://issues.redhat.com/browse/QUARKUS-7183
- externalhttps://issues.redhat.com/browse/QUARKUS-7209
- externalhttps://issues.redhat.com/browse/QUARKUS-7210
- externalhttps://issues.redhat.com/browse/QUARKUS-7211
- externalhttps://issues.redhat.com/browse/QUARKUS-7212
- externalhttps://issues.redhat.com/browse/QUARKUS-7213
- externalhttps://issues.redhat.com/browse/QUARKUS-7214
- externalhttps://issues.redhat.com/browse/QUARKUS-7215
- externalhttps://issues.redhat.com/browse/QUARKUS-7216
- externalhttps://issues.redhat.com/browse/QUARKUS-7219
- externalhttps://issues.redhat.com/browse/QUARKUS-7220
- externalhttps://issues.redhat.com/browse/QUARKUS-7221
- externalhttps://issues.redhat.com/browse/QUARKUS-7222
- externalhttps://issues.redhat.com/browse/QUARKUS-7223
- externalhttps://issues.redhat.com/browse/QUARKUS-7224
- externalhttps://issues.redhat.com/browse/QUARKUS-7225
- externalhttps://issues.redhat.com/browse/QUARKUS-7226
- externalhttps://issues.redhat.com/browse/QUARKUS-7227
- externalhttps://issues.redhat.com/browse/QUARKUS-7228
- externalhttps://issues.redhat.com/browse/QUARKUS-7312
- externalhttps://issues.redhat.com/browse/QUARKUS-7313
- externalhttps://issues.redhat.com/browse/QUARKUS-7314
- externalhttps://issues.redhat.com/browse/QUARKUS-7315
- externalhttps://issues.redhat.com/browse/QUARKUS-7316
- externalhttps://issues.redhat.com/browse/QUARKUS-7317
- externalhttps://issues.redhat.com/browse/QUARKUS-7318
- externalhttps://issues.redhat.com/browse/QUARKUS-7319
- externalhttps://issues.redhat.com/browse/QUARKUS-7320
- externalhttps://issues.redhat.com/browse/QUARKUS-7321
- externalhttps://issues.redhat.com/browse/QUARKUS-7348
- externalhttps://issues.redhat.com/browse/QUARKUS-7349
- externalhttps://issues.redhat.com/browse/QUARKUS-7350
- externalhttps://issues.redhat.com/browse/QUARKUS-7351
- externalhttps://issues.redhat.com/browse/QUARKUS-7352
- externalhttps://issues.redhat.com/browse/QUARKUS-7378
- externalhttps://issues.redhat.com/browse/QUARKUS-7491
- externalhttps://issues.redhat.com/browse/QUARKUS-7494
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7380.json