CVE-2026-93432: Red Hat Exploit Intelligence

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This vulnerability can lead to Cross-Site Scripting (XSS) and JSON Injection, potentially allowing a remote attacker to execute arbitrary code in a user's browser or manipulate data.

Affected products

  • Red Hat Exploit Intelligence
  • Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
  • Red Hat Red Hat Build Of Apicurio Registry 3
  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Quarkus
  • Red Hat Red Hat Fuse 7

Published 2026-09-18. Last modified 2026-09-18.