CVE-2026-93432 Overview
CVE-2026-93432 affects the Quarkus Qute template engine. The {#eval} section helper fails to propagate the parent template's content type when processing a sub-template. This gap disables the standard context-aware escaping that Qute normally applies, allowing untrusted input to render as raw output.
The defect enables Cross-Site Scripting (XSS) [CWE-79] and JSON Injection against applications that use {#eval} with attacker-influenced data. Remote attackers can execute arbitrary script in a victim's browser session or inject values that corrupt structured responses. The issue requires user interaction and has a network attack vector.
Critical Impact
Applications rendering user-supplied content through {#eval} in Qute templates can serve unescaped payloads, exposing users to XSS and JSON Injection attacks.
Affected Products
- Quarkus framework distributions that ship the Qute template engine
- Applications and services embedding Qute for HTML or JSON rendering
- Red Hat build of Quarkus (per Red Hat advisory tracking)
Discovery Timeline
- 2026-09-18 - CVE-2026-93432 published to the National Vulnerability Database (NVD)
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-93432
Vulnerability Analysis
Qute applies content-type-aware escaping so that variables rendered inside an HTML template are HTML-escaped, and variables inside a JSON template are JSON-escaped. This behavior depends on the engine knowing the parent template's content type at render time.
The {#eval} section helper compiles and executes a template fragment supplied at runtime. When it delegates to the sub-template, it does not forward the parent template's content type metadata. The sub-template therefore falls back to a raw output mode with no escaping applied.
Any expression rendered inside the evaluated fragment reaches the response body verbatim. In HTML responses, that means <script> tags and event handlers execute in the victim's browser. In JSON responses, injected quotes or braces break the document structure and can smuggle attacker-controlled fields.
Root Cause
The root cause is missing content type propagation between the parent template and the sub-template invoked by {#eval}. Escaping in Qute is selected based on that content type, so losing it silently converts a safe rendering path into an unsafe one. This is a classic Improper Neutralization of Input During Web Page Generation weakness [CWE-79].
Attack Vector
An attacker submits crafted input, such as a form field, query parameter, or API payload, that reaches a template rendered through {#eval}. The application returns the response to a victim who interacts with it, satisfying the user interaction requirement. The scope change reflects that script executes in the browser trust boundary rather than the server. Details of the exploitation surface are described in the Red Hat CVE-2026-93432 Advisory.
Detection Methods for CVE-2026-93432
Indicators of Compromise
- Unexpected <script>, onerror, or onload fragments in server responses generated from Qute templates.
- Malformed JSON responses containing unescaped quotes or injected keys from user-controlled fields.
- Application logs showing template render errors or content type mismatches around {#eval} calls.
Detection Strategies
- Perform code review across the repository for occurrences of {#eval} in Qute templates and confirm whether the rendered fragment depends on untrusted input.
- Add automated tests that submit HTML and JSON payloads to endpoints backed by {#eval} and assert that reserved characters are escaped.
- Enable web application firewall rules that flag reflected script patterns and unbalanced JSON structures on Quarkus routes.
Monitoring Recommendations
- Monitor outbound HTTP responses for reflected user input that bypasses content-type-appropriate escaping.
- Alert on browser Content Security Policy violations reported by clients consuming Quarkus applications.
- Track anomalies in JSON parse failures on downstream consumers, which can indicate injection into structured responses.
How to Mitigate CVE-2026-93432
Immediate Actions Required
- Inventory all Quarkus applications and identify templates that use the {#eval} section helper.
- Restrict {#eval} to trusted, developer-controlled fragments and remove any use of it against user-influenced strings.
- Apply the Quarkus Qute update referenced in the Red Hat CVE-2026-93432 Advisory once available for your distribution.
Patch Information
Red Hat tracks remediation for this vulnerability under the Red Hat Bug Report #2536859 and the associated CVE advisory. Consult your Quarkus vendor channel for the fixed version and apply it to all affected services. Redeploy container images and rebuild native executables so the updated Qute engine is loaded.
Workarounds
- Refactor templates to replace {#eval} with static sub-templates that inherit the parent content type by design.
- Sanitize any input that must reach a dynamically evaluated fragment using an HTML or JSON encoder before insertion.
- Enforce a strict Content Security Policy that blocks inline scripts to reduce the blast radius of any residual XSS.
# Configuration example
# Locate templates that invoke {#eval} for review
grep -R "{#eval" src/main/resources/templates/
# Enforce a strict CSP header for Quarkus HTTP responses
# application.properties
quarkus.http.header."Content-Security-Policy".value=default-src 'self'; script-src 'self'; object-src 'none'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
