quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 취약점
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.
영향 제품·버전
제품 quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1
영향 버전 quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 >= >= 3.36.0, < 3.36.3, >= >= 3.33.0, < 3.33.2.1, >= >= 3.27.0, < 3.27.4.1, >= < 3.20.6.2, < 3.20.6.2, >= 3.21.0 < 3.27.4.1, >= 3.28.0 < 3.33.2.1, >= 3.34.0 < 3.36.3
수정 버전 quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3
quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1의 현재 전체 버전이 공식 영향 범위(quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 >= >= 3.36.0, < 3.36.3, >= >= 3.33.0, < 3.33.2.1, >= >= 3.27.0, < 3.27.4.1, >= < 3.20.6.2, < 3.20.6.2, >= 3.21.0 < 3.27.4.1, >= 3.28.0 < 3.33.2.1, >= 3.34.0 < 3.36.3)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
저장소 Security Advisory 원문에서 CVE 번호가 CVE-2026-50559와 일치하는지 먼저 확인하고, 일치할 때만 수정 버전 값(3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3)을 조치 기준으로 사용합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 quarkusio quarkus, Cryostat 4 on RHEL 9, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3 기준을 충족하는지 확인합니다. 이어서 인증 우회 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.