Vulnerabilities > Quarkus > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-01-25 CVE-2023-6267 Improper Handling of Exceptional Conditions vulnerability in Quarkus
A flaw was found in the json payload.
network
low complexity
quarkus CWE-755
critical
9.8
2023-12-09 CVE-2023-6394 Missing Authorization vulnerability in multiple products
A flaw was found in Quarkus.
network
low complexity
quarkus redhat CWE-862
critical
9.1
2022-11-22 CVE-2022-4116 A vulnerability was found in quarkus.
network
low complexity
redhat quarkus
critical
9.8
2022-08-31 CVE-2022-2466 HTTP Request Smuggling vulnerability in Quarkus
It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.
network
low complexity
quarkus CWE-444
critical
9.8
2022-02-02 CVE-2022-21724 Improper Initialization vulnerability in multiple products
pgjdbc is the offical PostgreSQL JDBC Driver.
network
low complexity
postgresql fedoraproject quarkus debian CWE-665
critical
9.8
2021-04-23 CVE-2021-26291 Origin Validation Error vulnerability in multiple products
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository.
network
low complexity
apache quarkus oracle CWE-346
critical
9.1