Path Traversal Vulnerability in Quarkus OpenAPI Generator by Quarkus
CVE-2026-40180

7.7HIGH

Key Information:

Vendor
CVE Published:
10 April 2026

What is CVE-2026-40180?

The Quarkus OpenAPI Generator contains a vulnerability in its unzip() method, which allows for path traversal through malicious ZIP entries. Prior to versions 2.16.0 and 2.15.0-lts, the method improperly handles file extraction, enabling attackers to exploit this weakness by crafting ZIP files that include path traversal sequences, such as ../../. This flaw permits unauthorized writing of files outside the designated output directory, exposing systems to potential data breaches and integrity issues. Users are encouraged to upgrade to the patched versions to mitigate risks associated with this vulnerability.

Affected Version(s)

quarkus-openapi-generator < 2.15.0-lts < 2.15.0-lts

quarkus-openapi-generator < 2.16.0 < 2.16.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.