6.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts, and 2.17.0, the generated authentication filter matches OpenAPI path templates too broadly when deciding whether to attach credentials. A security scheme configured for one operation can therefore be applied to a different same-method operation whose path only partially resembles the protected template, causing bearer tokens, API keys, or basic credentials to be sent to unintended endpoints. This issue has been patched in versions 2.11.1-lts, 2.16.0-lts, and 2.17.0.
Basic Information
ID
CVE-2026-42333
Source
GitHub_M
Published
May 9, 2026 at 19:16
Affected Product
Vendor
quarkiverse
Product
quarkus-openapi-generator
Version
< 2.11.1-lts
Affected Versions
quarkiverse quarkus-openapi-generator < 2.11.1-lts
quarkiverse quarkus-openapi-generator < 2.16.0-lts
quarkiverse quarkus-openapi-generator < 2.17.0
quarkiverse quarkus-openapi-generator < 2.16.0-lts
quarkiverse quarkus-openapi-generator < 2.17.0
CWE Classification
References
- github.com /quarkiverse/quarkus-openapi-generator/security/advisories/GHSA-fr8f-rwjx-f32v
- github.com /quarkiverse/quarkus-openapi-generator/pull/1586
- github.com /quarkiverse/quarkus-openapi-generator/releases/tag/2.11.1-lts
- github.com /quarkiverse/quarkus-openapi-generator/releases/tag/2.16.0-lts
- github.com /quarkiverse/quarkus-openapi-generator/releases/tag/2.17.0