Skip to main content
Vulnerability Database/CVE-2026-87743

CVE-2026-87743: Quarkus HTTP Auth Bypass Vulnerability

CVE-2026-87743 is an authentication bypass flaw in Quarkus HTTP security that lets attackers access protected endpoints by exploiting path normalization differences. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-87743 Overview

CVE-2026-87743 is an authorization bypass vulnerability in Quarkus HTTP security. The flaw stems from a discrepancy in how URL paths are normalized between the security matcher and the HTTP request dispatchers. An unauthenticated remote attacker can craft a URL that the security matcher classifies as public, while the underlying dispatcher routes the request to a protected endpoint. Successful exploitation grants unauthorized access to sensitive information exposed by endpoints that should require authentication. The weakness is classified under CWE-551: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization.

Critical Impact

Unauthenticated attackers can bypass Quarkus HTTP authorization checks over the network and access protected endpoints without credentials.

Affected Products

Discovery Timeline

  • 2026-09-18 - CVE CVE-2026-87743 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-87743

Vulnerability Analysis

Quarkus enforces HTTP authorization through a security matcher that maps incoming request paths to policy rules. The dispatcher layer that ultimately routes a request to a Jakarta REST or servlet handler applies its own path normalization logic. When these two layers disagree on the canonical form of a path, an attacker can construct a URL that passes the security matcher as unauthenticated-safe while the dispatcher resolves it to a protected resource. The result is a network-reachable authorization bypass that requires no privileges and no user interaction. Because the flaw exposes protected endpoint data, the primary impact is confidentiality loss for information that should sit behind authentication.

Root Cause

The root cause is inconsistent path canonicalization between two components in the same request pipeline. The security matcher normalizes and evaluates a path against policy before the dispatcher performs its own normalization step. Sequences such as encoded separators, redundant slashes, . and .. segments, or trailing constructs can be interpreted differently by each layer. This mismatch aligns with CWE-551, where authorization is applied before full canonicalization.

Attack Vector

Exploitation occurs over the network against any Quarkus application that relies on HTTP path-based security rules. An unauthenticated attacker sends a crafted HTTP request whose URL is shaped to satisfy a public rule in the security matcher while still resolving to a protected handler after dispatcher normalization. No authentication, tokens, or user interaction are required. Refer to Red Hat Bug Report #2530523 and the Red Hat CVE Analysis CVE-2026-87743 for technical detail on the affected code paths.

Detection Methods for CVE-2026-87743

Indicators of Compromise

  • Unauthenticated HTTP requests that successfully reach endpoints normally protected by Quarkus HTTP security policies.
  • Access log entries containing unusual path encodings such as %2e, %2f, .., doubled slashes, or trailing segments targeting protected routes.
  • Response codes of 200 on protected paths from clients that never completed authentication.

Detection Strategies

  • Compare request paths at the reverse proxy and application layers to surface normalization mismatches on protected routes.
  • Alert when access logs show 2xx responses to sensitive endpoints without a preceding authentication event in identity or session logs.
  • Deploy application-layer rules that flag encoded path traversal patterns and duplicate separators targeting Quarkus services.

Monitoring Recommendations

  • Ingest Quarkus access and security logs into a centralized analytics platform and baseline expected authenticated traffic to sensitive endpoints.
  • Monitor for spikes in 401-to-200 transitions and for repeated probing of API paths with obfuscated characters.
  • Track upstream WAF or ingress logs for path-normalization anomalies and correlate them with backend Quarkus responses.

How to Mitigate CVE-2026-87743

Immediate Actions Required

  • Apply the Quarkus updates referenced in RHSA-2026:69440 and RHSA-2026:69470 as soon as they are available in your environment.
  • Inventory all Quarkus services that rely on HTTP path-based authorization policies and prioritize patching internet-facing instances.
  • Review recent access logs for suspicious unauthenticated access to protected endpoints and rotate any credentials or tokens that may have been exposed.

Patch Information

Red Hat has published patched builds through RHSA-2026:69440 and RHSA-2026:69470. Consult the Red Hat CVE Analysis CVE-2026-87743 for the definitive list of fixed component versions and product streams.

Workarounds

  • Enforce authorization inside endpoint handlers using role annotations rather than relying solely on HTTP path matchers.
  • Place a reverse proxy or WAF in front of Quarkus that normalizes paths, rejects encoded traversal sequences, and blocks duplicate separators before requests reach the application.
  • Restrict network exposure of sensitive endpoints to trusted networks until patches are applied.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.