DEV Community

endoflife-ai
endoflife-ai

Posted on • Originally published at endoflife.ai

Quarkus Authorization Bypass (CVE-2026-39852): The Fix That 50+ EOL Versions Will Never Get

A CVSS 8.2 authorization bypass in Quarkus is fixed in current releases — but of the 58 Quarkus release lines we track, 55 are past end of life, and the entire 2.x family will never see the patch. Which versions are fixed, which are stranded, and the real options for each.

Fixed vs. stranded

Where you are Status Your move
3.35.2+, 3.38 (current) Fixed & supported Update normally
3.33 LTS Fixed in 3.33.1.1 · supported to Mar 2027 Patch to 3.33.1.1+
3.27 Fixed in 3.27.3.1 Patch, plan move to LTS
3.20 LTS Fix exists (3.20.6.1) · community window closed Mar 28, 2026 Apply fix, migrate to 3.33 LTS
Any other 3.x minor EOL — no fixed build in your line Upgrade to a fixed line
Any 2.x EOL since 2023 or earlier — no fix, ever Migrate or extended support

What's covered

  • Why so many Quarkus versions are EOL
  • The 2.x family: end of the line, permanently
  • Fixed vs. stranded
  • The bigger pattern

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-quarkus-eol

Top comments (0)