CVE-2023-4853: Quarkus

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

Affected products

  • Quarkus Quarkus: before 2.16.11 (fixed in 2.16.11); from 3.2.0, before 3.2.6 (fixed in 3.2.6); from 3.3.0, before 3.3.3 (fixed in 3.3.3)
  • Red Hat Build Of Optaplanner: version 8.0 only
  • Red Hat Build Of Quarkus: from 2.13.0, before 2.13.8 (fixed in 2.13.8)
  • Red Hat Decision Manager: version 7.0 only
  • Red Hat Integration Camel K: before 1.10.2 (fixed in 1.10.2)
  • Red Hat Integration Camel Quarkus: affected versions not specified
  • Red Hat Integration Service Registry: affected versions not specified
  • Red Hat JBoss Middleware: version 1 only
  • Red Hat JBoss Middleware Text-Only Advisories: version 1.0 only
  • Red Hat Openshift Container Platform: version 4.10 only; version 4.11 only; version 4.12 only
  • Red Hat Openshift Serverless: affected versions not specified; version 1.0 only
  • Red Hat Process Automation Manager: version 7.0 only

Published 2023-09-20. Last modified 2026-08-04.