← All Advisories

CVE-2026-87743

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-87743

Key Details

CVECVE-2026-87743
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsRed Hat Red Hat OpenShift Dev Spaces
Classified asCWE-551 (Incorrect Behavior Order: Authorization Before Parsing and Canonicalization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift Dev Spaces
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the security matcher considers public, but which is then routed to a protected endpoint, leading to an authorization bypass and potential unauthorized access to sensitive information. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-87743
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-87743