Ibm Enterprise Build Of Quarkus vulnerabilities
4 known vulnerabilities affecting ibm/enterprise_build_of_quarkus.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-77874P2HIGHCVSS 8.6≥ 3.27.1, ≤ 3.27.5.SP1≥ 3.33.1, ≤ 3.33.3.SP12026-09-24
CVE-2026-77874 [HIGH] CWE-89 CVE-2026-77874: IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerab
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
nvd
CVE-2026-19651P3HIGHCVSS 7.4≥ 3.27.1, ≤ 3.27.5≥ 3.33.1, ≤ 3.33.32026-09-08
CVE-2026-19651 [HIGH] CWE-639 CVE-2026-19651: IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an att
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
nvd
CVE-2026-16308P3HIGHCVSS 7.5≥ 3.27.1, ≤ 3.27.4.SP2≥ 3.33.1, ≤ 3.33.2.SP22026-07-30
CVE-2026-16308 [HIGH] CWE-770 CVE-2026-16308: IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus RES
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
nvd
CVE-2026-19625P4MEDIUMCVSS 5.3≥ 3.27.1, ≤ 3.27.5≥ 3.33.1, ≤ 3.33.32026-09-08
CVE-2026-19625 [MEDIUM] CWE-284 CVE-2026-19625: When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to ac
nvd