Red Hat build of Quarkus
The Red Hat build of Quarkus is based on the popular Quarkus community project. It's Kubernetes-native Java with low memory footprint and fast boot times for microservices and serverless applications.
browse_doc
Learn what's new in 3.33Discover
Build your first applicationGet started
Migrate applications to 3.33Migrate
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cve(RHSA-2026:47172) Important: Red Hat build of Quarkus 3.33.2.SP3 security update | synopsis Important: Red Hat build of Quarkus 3.33.2.SP3 security update | date |
| severity Important | advisory_cve(RHSA-2026:47189) Important: Red Hat build of Quarkus 3.27.4.SP3 security update | synopsis Important: Red Hat build of Quarkus 3.27.4.SP3 security update | date |
| severity Important | advisory_cveCVE-2026-64641 | synopsis A flaw was found in Next.js, a React framework for building web applications. A remote attacker can send specially crafted requests to Next.js applications that utilize the App Router with Server Actions. This can lead to excessive CPU usage, causing the application to become unresponsive and preventing it from processing further requests, resulting in a Denial of Service (DoS). | date |
| severity Important | advisory_cveCVE-2026-56624 | synopsis A flaw was found in Apache MINA SSHD (server-side). During user authentication, the server's OpenSSH user certificate validation process failed to properly check for or validate unsupported options like 'force-command' or 'verify-required' embedded within a user's certificate. This oversight could allow an authenticated user to bypass intended restrictions and execute commands beyond those specified in their certificate, potentially leading to unauthorized actions on the server. | date |
| severity Moderate | advisory_cveCVE-2026-59888 | synopsis A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter, even if it was intended to be ignored. Consequently, an untrusted client could set internal or privileged components from external input, potentially leading to unauthorized modification or disclosure of sensitive data. | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.