CVE-2026-50559: Authentication and Authorization Bypass via Parser Differential in Quarkus
Vulnerability ID: CVE-2026-50559
CVSS Score: 7.5
Published: 2026-07-29
A critical authentication and authorization bypass vulnerability in the Quarkus Java framework exists due to a parser differential mismatch between the HTTP security policy layer and downstream handlers. By leveraging encoded reserved characters such as semicolons, slashes, and backslashes, attackers can bypass configured path-based security policies to gain unauthorized access to secure administrative endpoints and static resources.
TL;DR
Quarkus applications prior to 3.37.0 are vulnerable to an authentication bypass where encoded characters (%3B, %2F, %5C) prevent security filters from matching path-based policies, while downstream routers decode and execute the requests.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-287 / CWE-863
- Attack Vector: Network
- CVSS v3.1 Score: 7.5 (High)
- EPSS Score: 0.00463 (37.7th percentile)
- Impact: Authentication & Authorization Bypass
- Exploit Status: Proof of Concept (PoC) Available
- CISA KEV Status: Not Listed
Affected Systems
- Quarkus Java Framework
Mitigation Strategies
- Upgrade to a patched version of Quarkus (3.37.0, 3.36.3, 3.33.2.1, 3.27.4.1, 3.20.6.2)
- Configure Web Application Firewall (WAF) or API Gateway edge rules to block encoded reserved characters (%3B, %2F, %5C)
- Adopt programmatic method-level authorization annotations (@RolesAllowed) as a defense-in-depth measure
Remediation Steps:
- Identify all Quarkus deployments within the application environment.
- Update application build configurations (pom.xml or build.gradle) to reference a secure, patched Quarkus version.
- Verify the deployment by running integration tests targeting path-based security policies.
- Deploy perimeter WAF rules to inspect and sanitize HTTP URIs before they reach the application cluster.
- Perform method-level security reviews and transition from path-based authorization to programmatic annotations where applicable.
Read the full report for CVE-2026-50559 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)