Quarkus 3.27.5 has been released as a maintenance update for the 3.27 LTS stream. The release focuses heavily on security, patching 18 CVEs across Quarkus direct dependencies and Netty (upgraded to 4.1.136.Final). Notable fixes include Eclipse Vert.x cross-origin header propagation and cross-domain cookie injection, Jackson-databind annotation bypass vulnerabilities, an authentication downgrade in OnGres SCRAM, a SQL injection in LangChain4j, and numerous Netty issues including zip bomb, CR/LF injection, memory exhaustion, and CORS access control flaws. The update is considered safe for existing 3.27 users and can be applied via the Quarkus CLI.
1.8K Impressions