Impact
The vulnerability resides in Quarkus HTTP security where a mismatch between the path normalization used by the security matcher and the HTTP request dispatcher permits an unauthenticated attacker to craft a URL that is treated as public by the matcher yet routed to a protected endpoint. This flaw enables an attacker to bypass authorization controls and access sensitive information. The weakness is a path normalization error, as identified by CWE-551.
Affected Systems
Red Hat builds and derivatives of Quarkus, including Quarkus 3, Apicurio Registry 3, Camel 4 for Quarkus 3, Debezium 3, Keycloak build, and Red Hat OpenShift Serverless, Dev Spaces, OpenShift AI, OpenShift Build of Apache Camel, and Red Hat Fuse 7. All products that incorporate the Quarkus HTTP security component are affected in the versions listed by the vendor advisories.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a medium‑to‑high risk vulnerability, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The flaw is not listed in CISA’s KEV catalog, indicating no publicly known exploits at this time. Attacks would likely involve sending a specially crafted HTTP request to the target service, exploiting the path normalization discrepancy to reach a protected resource that ought to be secured.
OpenCVE Enrichment