IBM Enterprise Build Of Quarkus
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Enterprise Build Of Quarkus.
By the Year
In 2026 there have been 3 vulnerabilities in IBM Enterprise Build Of Quarkus with an average score of 6.7 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 6.73 |
It may take a day or so for new Enterprise Build Of Quarkus vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Enterprise Build Of Quarkus Security Vulnerabilities
Quarkus OIDC Introspection Cache Enables CrossTenant Token Use
CVE-2026-19625
5.3 - Medium
- September 08, 2026
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Authorization
IBM Quarkus 3.27.x-3.27.5 / 3.33.x Auth Bypass via URL Query
CVE-2026-19651
7.4 - High
- September 08, 2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
Insecure Direct Object Reference / IDOR
IBM Quarkus REST DoS via Unbounded MIME Header Accum (3.27,3.33)
CVE-2026-16308
7.5 - High
- July 30, 2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
Allocation of Resources Without Limits or Throttling
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Enterprise Build Of Quarkus or by IBM? Click the Watch button to subscribe.