Quarkus 3.33.3 released - LTS maintenance release
Today, we released Quarkus 3.33.3, our next maintenance release for the 3.33 LTS stream.
This release contains bugfixes, documentation updates, and security fixes.
It should be a safe upgrade for anyone already using 3.33.
Security fixes
This release fixes the following CVEs:
Quarkus and direct dependencies
-
CVE-2026-15075 - Eclipse Vert.x:
DefaultRedirectHandlercross-origin header propagation -
CVE-2026-15076 - Eclipse Vert.x:
WebClientSessioncross-domain cookie injection -
CVE-2026-54291 - pgjdbc: Channel binding downgrade vulnerability
-
CVE-2026-53712 - OnGres SCRAM client: Authentication downgrade
-
CVE-2026-59888 - Jackson-databind:
@JsonIgnorebypass withPropertyNamingStrategyon Java Records -
CVE-2026-59889 - Jackson-databind:
@JsonViewbypass for@JsonUnwrappedproperties during deserialization -
CVE-2026-8484 - Jansi: Heap-based buffer overflow in JNI ioctl() wrapper
-
CVE-2026-55405 - LangChain4j: SQL injection in embedding store metadata filter
Netty
This release upgrades Netty to 4.1.136.Final, which fixes numerous security vulnerabilities including:
-
CVE-2026-55833 - Zip bomb vulnerability in
netty-codec-http -
CVE-2026-59921 - Improper CR/LF neutralization in
netty-codec-http(multipart) -
CVE-2026-59919 - Improper CR/LF neutralization in
netty-codec-haproxy -
CVE-2026-55851 - Memory exhaustion in
netty-codec-haproxy -
CVE-2026-56745 - Memory exhaustion in
netty-codec-http -
CVE-2026-59899 - Memory exhaustion in
netty-codec-http -
CVE-2026-55831 - Resource exhaustion/DoS in
netty-codec-http -
CVE-2026-56819 - Memory leak in
netty-codec-http2 -
CVE-2026-59900 - Improper header neutralization in
netty-codec-http2 -
CVE-2026-59898 - Protocol version confusion in
netty-codec-http(websocket) -
CVE-2026-56746 - Improper access control in
netty-codec-http(CORS)
For the full list, see the Netty 4.1.136.Final release announcement.
Actualización
To update to Quarkus 3.33, we recommend updating to the latest version of the Quarkus CLI and run:
quarkus update --stream=3.33
Note that quarkus update can update your applications from any version of Quarkus (including 2.x) to Quarkus 3.33.
Registro completo de cambios
You can get the full changelog of 3.33.3 on GitHub.
Únete a nosotros
Valoramos mucho tus comentarios, así que por favor reporta errores, solicita mejoras… ¡Construyamos algo grandioso juntos!
Si eres un usuario de Quarkus o simplemente tienes curiosidad, no seas tímido y únete a nuestra acogedora comunidad:
-
proporcionar retroalimentación en GitHub;
-
escribir algo de código y enviar push a PR;
-
comentar con nosotros en Zulip y en nuestra lista de correo;
-
hacer tus preguntas en Stack Overflow.