Red Hat Product Errata RHSA-2026:23808 - Security Advisory Issued: 2026-06-10 Updated: 2026-06-10 RHSA-2026:23808 - Security Advisory Overview Synopsis Important: Red Hat build of Quarkus 3.27.4 release and security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section. Description This release of Red Hat build of Quarkus 3.27.4 includes the following CVE fixes: netty-codec-dns: Netty: High integrity impact due to improper DNS domain name constraint enforcement [quarkus-3.27] (CVE-2026-42579) netty-codec- http: Netty: Incorrect HTTP response parsing leads to data confusion [quarkus-3.27] (CVE-2026-42584) netty-codec- http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers [quarkus-3.27] (CVE-2026-42581) netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation [quarkus-3.27] (CVE-2026-42578) netty-codec- http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression [quarkus-3.27] (CVE-2026-42587) netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression [quarkus-3.27] (CVE-2026-42587) For more information, see the release notes page listed in the References section. Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat build of Quarkus Text-Only Advisories x86_64 Fixes QUARKUS-6793 - [Migration to 3.27] Random test failures during the CI QUARKUS-7610 - Graceful shutdown process stalls until quarkus.shutdown.timeout is reached since 3.27.3.redhat-00003 QUARKUS-7615 - [3.27] Upgrade to Jackson 2.21.2 QUARKUS-7616 - [3.27] Bump Agroal to 2.8.1 QUARKUS-7617 - [3.27] Upgrade to Vert.x 4.5.26 and Netty 4.1.132.Final QUARKUS-7618 - [3.27] Update to plexus-utils 3.6.1 QUARKUS-7619 - [3.27] Bump kafka3.version from 4.0.0 to 4.0.2 QUARKUS-7620 - Bump bouncycastle to 1.84 QUARKUS-7621 - Properly configure Jackson shutdown listener QUARKUS-7622 - Catch StreamConstraintsException in Jackson message body readers QUARKUS-7623 - Fix path templating issue for overlapping paths QUARKUS-7624 - Ensure that invalid forwarded headers results in HTTP 400 QUARKUS-7625 - Do not create a public key in devmode when 'smallrye.jwt.verify.key.location' is set QUARKUS-7626 - Fix Oracle connection rollback interceptor QUARKUS-7627 - Use getRecommended() when displaying platforms to be imported in quarkus info command QUARKUS-7628 - [3.27] Fix flaky LRA TCK tests QUARKUS-7630 - Remove the org.lz4 exclusion, it's no longer necessary QUARKUS-7631 - Remove the tech preview note from reactive-sql-clients.adoc QUARKUS-7632 - [3.27] Quarkus REST: fix @Context injection for records into 3.27 QUARKUS-7633 - [3.27] Bump the hibernate group with 7 updates QUARKUS-7664 - [3.27] Bump the hibernate group with 8 updates QUARKUS-7774 - [3.27] Strip matrix parameters from request paths during HTTP security policy matching QUARKUS-7775 - Bump org.postgresql:postgresql from 42.7.7 to 42.7.8 QUARKUS-7776 - Upgrade to PostgreSQL JDBC 42.7.9 QUARKUS-7777 - build(deps): bump org.postgresql:postgresql from 42.7.9 to 42.7.10 QUARKUS-7778 - Bump postgresql-jdbc.version to 42.7.11 QUARKUS-7779 - Bump to Vert.x 4.5.27 and Netty 4.1.133.Final QUARKUS-7780 - Bump to quarkus-http 5.5.0 QUARKUS-7781 - Fix Jakarta Transaction link on transaction.adoc documentation QUARKUS-7812 - [3.27] Bump the hibernate group with 7 updates QUARKUS-7813 - [3.27] Pin actions to specific shas, and avoid using external actions when we can CVEs CVE-2026-42578 CVE-2026-42579 CVE-2026-42581 CVE-2026-42584 CVE-2026-42587 References https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/products/quarkus/ https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.27.4 https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.27 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This security update for Red Hat build of Quarkus 3.27.4 addresses multiple vulnerabilities in the bundled Netty library, including HTTP request smuggling (CVE-2026-42581, CVSS 5.8), HTTP header injection (CVE-2026-42578), and denial of service via unbounded memory allocation (CVE-2026-42587). The underlying Netty library vulnerabilities affect versions prior to 4.1.133 and 4.2.0 through 4.2.12, which are resolved by upgrading Netty to version 4.1.133 or 4.2.13. The fix is applied by updating to Red Hat build of Quarkus 3.27.4.