Data Leakage Vulnerability in Quarkus Java Framework
CVE-2025-49574

6.4MEDIUM

Key Information:

Vendor

Quarkusio

Status
Vendor
CVE Published:
23 June 2025

What is CVE-2025-49574?

The Quarkus framework, utilized for developing cloud-native Java applications, is subject to a data leakage issue in versions before 3.24.0. This vulnerability arises when duplicating a duplicated context, potentially allowing new transactional data to leak into previously existing transaction data. This can expose sensitive information such as request scopes, security details, and metadata. Although the occurrence of duplicating a duplicated context is relatively rare, the implications on data integrity are significant. The issue has since been addressed and patched in version 3.24.0.

Affected Version(s)

quarkus < 3.24.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49574 : Data Leakage Vulnerability in Quarkus Java Framework