Quarkus 3.33.3 has been released as a maintenance update for the 3.33 LTS stream. The release focuses heavily on security, patching 19 CVEs across Quarkus direct dependencies and Netty (upgraded to 4.1.136.Final). Notable fixes include Eclipse Vert.x cross-origin header propagation and cross-domain cookie injection, pgjdbc channel binding downgrade, Jackson-databind @JsonIgnore and @JsonView bypasses, a Jansi heap buffer overflow, a LangChain4j SQL injection, and numerous Netty vulnerabilities covering zip bombs, CR/LF injection, memory exhaustion, and improper access control. Upgrading via the Quarkus CLI with the 3.33 stream flag is recommended.
2.8K Impressions