Quarkus is a Kubernetes-native Java framework designed for building cloud-native applications, and despite a narrowly focused product portfolio, has risen to prominence in the enterprise Java application-deployment landscape. Vulnerabilities affecting the framework skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the security-sensitive role of a widely-embedded application runtime and the complexity of HTTP parsing and request-handling logic. The exposure recurs through weakness classes including HTTP request smuggling, improper input validation, inconsistent request interpretation, and insecure temporary-file handling—attack surfaces inherent to a request-processing middleware. Defenders should treat Quarkus advisories as high-priority for affected deployments, particularly when instances are internet-exposed or handle untrusted input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quarkus over time
Signals from CVEs in this vendor scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4116CRITICAL A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution. | Nov 22, 2022 | 9.8 | 47 | NO | NO |
CVE-2017-18640HIGH The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564. | Dec 12, 2019 | 7.5 | 38 | NO | NO |
CVE-2026-39852HIGH Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsiste | May 5, 2026 | 8.2 | 35 | NO | NO |
CVE-2022-21724CRITICAL pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql li | Feb 2, 2022 | 9.8 | 34 | NO | NO |
CVE-2021-26291CRITICAL Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a maliciou | Apr 23, 2021 | 9.1 | 34 | NO | NO |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 34 | NO | NO |
CVE-2026-50559HIGH Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based auth | Jun 19, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-2466CRITICAL It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior. | Aug 31, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-37714HIGH jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on u | Aug 18, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-21295MEDIUM Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.net | Mar 9, 2021 | 5.9 | 30 | NO | NO |
Signals from CVEs in this vendor scope (49 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quarkus.
Media articles that mention a CVE ID that affects a product developed by Quarkus — matched by CVE ID, not by vendor name.