CVE-2026-19651

Description

A flaw was found in quarkus-spring-web. A remote attacker could exploit this vulnerability by manipulating the URL query string. The system incorrectly reads the URL query string as a request header, which can lead to an authorization bypass, allowing unauthorized access to resources.

Statement

Important: This flaw in quarkus-spring-web allows for an authorization bypass by incorrectly interpreting URL query string parameters as request headers. This could enable unauthorized access to resources or functionality within applications utilizing the affected component, elevating the risk to Important due to the potential for privilege escalation or data exposure.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.