maven package report

Is io.quarkus:quarkus-rest-deployment safe?

1 known vulnerability, worst severity HIGH.

cvss
8.3

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
3.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-phg3-gv66-q38x, the advisory selected below

// advisories

GHSA-phg3-gv66-q38x

HIGHCVE-2025-1247

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

Affected
< 3.8.6.1, >= 3.16.0.CR1, < 3.18.2, >= 3.9.0.CR1, < 3.15.3.1
Fixed in
3.8.6.1
Weakness
CWE-488
Published
2025-02-13
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 01:54 UTC. The most recent advisory here was published 2025-02-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is io.quarkus:quarkus-rest-deployment safe? maven package security report | CyberXYZ