Today, we released Quarkus 3.27.5.3, an emergency release for the 3.27 LTS stream. This release fixes the following CVEs: CVE-2026-77874 - Hibernate ORM: SQL Injection via unescaped JSON path segment allows data exfiltration and authorization bypass CVE-2026-19611 - WildFly Elytron: Password keyspace reduction via NFKC fullwidth folding CVE-2026-81829 - SmallRye JWT: Unauthenticated same-origin SSRF via unsanitized JWT kid header in AwsAlbKeyResolver CVE-2026-87742 - Quarkus WebSockets Next: Denial of Service (OOM) via unbounded message buffering CVE-2026-87743 - Quarkus Vert.x HTTP: Authoriza
Quarkus 3.27.5.3 released - LTS emergency release
calendar_today
September 22, 2026
person
Jan Martiška (https://twitter.com/janmartiska)
domain
quarkus