Skip to content

Conversation

@jmartisk
Copy link
Contributor

** If you are updating a guide, please submit your pull request to the main repository: https://github.com/quarkusio/quarkus/tree/main/docs/src/main/asciidoc **

@github-actions
Copy link

github-actions bot commented Aug 18, 2025

🙈 The PR is closed and the preview is expired.


Today, we released CVE fixes releases for Quarkus 3.15 LTS and 3.20 LTS to address
https://nvd.nist.gov/vuln/detail/CVE-2025-55163[CVE-2025-55163].
The fix mitigates a vulnerability against DoS attacks over the HTTP/2 protocol.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok, here is the fun thing.... There is a debate whether or not it's a protocol CVE. The protocol author obviously said that it's not, but lots (all?) implementations are affected.

So, I would "reduce" the tone a bit:

"The releases contain a fix again st the CVE .... affecting the Quarkus HTTP/2 support."

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok, done

author: jmartisk
---

Today, we released CVE fixes releases for Quarkus 3.15 LTS and 3.20 LTS to address
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we list the 2 version numbers?

Also explain that it's an emergency release as described in the other blog post?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ok, done

@jmartisk jmartisk merged commit 9ec7434 into quarkusio:main Aug 18, 2025
1 check passed
@jmartisk jmartisk deleted the 3.20.2.1-3.15.6.1 branch August 18, 2025 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants