The English version of quarkus.io is the official project site. Translated sites are community supported on a best-effort basis.

Quarkus 3.33.3 released - LTS maintenance release

Today, we released Quarkus 3.33.3, our next maintenance release for the 3.33 LTS stream.

This release contains bugfixes, documentation updates, and security fixes.

It should be a safe upgrade for anyone already using 3.33.

Security fixes

This release fixes the following CVEs:

Quarkus and direct dependencies

  • CVE-2026-15075 - Eclipse Vert.x: DefaultRedirectHandler cross-origin header propagation

  • CVE-2026-15076 - Eclipse Vert.x: WebClientSession cross-domain cookie injection

  • CVE-2026-54291 - pgjdbc: Channel binding downgrade vulnerability

  • CVE-2026-53712 - OnGres SCRAM client: Authentication downgrade

  • CVE-2026-59888 - Jackson-databind: @JsonIgnore bypass with PropertyNamingStrategy on Java Records

  • CVE-2026-59889 - Jackson-databind: @JsonView bypass for @JsonUnwrapped properties during deserialization

  • CVE-2026-8484 - Jansi: Heap-based buffer overflow in JNI ioctl() wrapper

  • CVE-2026-55405 - LangChain4j: SQL injection in embedding store metadata filter

Netty

This release upgrades Netty to 4.1.136.Final, which fixes numerous security vulnerabilities including:

For the full list, see the Netty 4.1.136.Final release announcement.

Actualización

To update to Quarkus 3.33, we recommend updating to the latest version of the Quarkus CLI and run:

quarkus update --stream=3.33

Note that quarkus update can update your applications from any version of Quarkus (including 2.x) to Quarkus 3.33.

Registro completo de cambios

Únete a nosotros

Valoramos mucho tus comentarios, así que por favor reporta errores, solicita mejoras…​ ¡Construyamos algo grandioso juntos!

Si eres un usuario de Quarkus o simplemente tienes curiosidad, no seas tímido y únete a nuestra acogedora comunidad: