Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Quarkus

First CVE: Dec 12, 2019Active for: 7 yearsTotal CVEs: 49
46.8
VTI Score
High

Quarkus is a Kubernetes-native Java framework designed for building cloud-native applications, and despite a narrowly focused product portfolio, has risen to prominence in the enterprise Java application-deployment landscape. Vulnerabilities affecting the framework skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the security-sensitive role of a widely-embedded application runtime and the complexity of HTTP parsing and request-handling logic. The exposure recurs through weakness classes including HTTP request smuggling, improper input validation, inconsistent request interpretation, and insecure temporary-file handling—attack surfaces inherent to a request-processing middleware. Defenders should treat Quarkus advisories as high-priority for affected deployments, particularly when instances are internet-exposed or handle untrusted input. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
49
Total CVEs
More Total CVEs than 98% of tracked vendors
6.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Quarkus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2019
6 years ago
Most Recent CVE
Jun 19, 2026
36 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-4116CRITICAL
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.
Nov 22, 20229.847NONO
CVE-2017-18640HIGH
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
Dec 12, 20197.538NONO
CVE-2026-39852HIGH
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsiste
May 5, 20268.235NONO
CVE-2022-21724CRITICAL
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql li
Feb 2, 20229.834NONO
CVE-2021-26291CRITICAL
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a maliciou
Apr 23, 20219.134NONO
CVE-2020-25649HIGH
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi
Dec 3, 20207.534NONO
CVE-2026-50559HIGH
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based auth
Jun 19, 20267.533NONO
CVE-2022-2466CRITICAL
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
Aug 31, 20229.832NONO
CVE-2021-37714HIGH
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on u
Aug 18, 20217.530NONO
CVE-2021-21295MEDIUM
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.net
Mar 9, 20215.930NONO
View all 49 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products49 CVEs
39%
43%
14%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (10.2%)
Network43 (87.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low38 (77.6%)
High11 (22.4%)
Unknown0 (0.0%)
User Interaction
None45 (91.8%)
Unknown0 (0.0%)
Required4 (8.2%)
Privileges Required
Low10 (20.4%)
High3 (6.1%)
None36 (73.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Quarkus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Quarkus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Quarkus's Products

View all 10 CNAs →

Top CWEs