THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-39852 (HIGH 8.2) — Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged user

[NVD] CVE-2026-39852 (HIGH 8.2) — Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged user

lownvdPublished 2026-05-05

CVE-2026-39852 CVSS: 8.2 HIGH Published: 2026-05-05T21:16:22.823

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Qu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-39852