CVE-2026-19651
Description
A flaw was found in quarkus-spring-web. A remote attacker could exploit this vulnerability by manipulating the URL query string. The system incorrectly reads the URL query string as a request header, which can lead to an authorization bypass, allowing unauthorized access to resources.
Statement
Important: This flaw in quarkus-spring-web allows for an authorization bypass by incorrectly interpreting URL query string parameters as request headers. This could enable unauthorized access to resources or functionality within applications utilizing the affected component, elevating the risk to Important due to the potential for privilege escalation or data exposure.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.