Red Hat released updates for its Quarkus distributions to remediate CVE-2024-2700, which can cause build-time quarkus.* environment settings from developer or CI systems to be embedded in deployed applications. Unsafe test settings—such as permissive TLS trust or database-drop behavior—could therefore reach production unless explicitly overridden. The fixes are available in Red Hat build of Quarkus 3.8.4 and 3.2.12, and are also included in affected offerings such as AMQ Streams, RHOSS, HawtIO, and Apicurio Registry.
The releases also address CVE-2024-29025 in Netty netty-codec-http, where crafted chunked HTTP POST forms can force unbounded memory growth and cause denial of service. Red Hat’s Apicurio Registry 2.6.1 GA container-image update additionally fixes vulnerabilities in webpack-dev-middleware, Express, Jetty, and jose4j, including potential file disclosure and malformed-URL processing issues. Organizations should update affected Quarkus-based products and container images, applying prerequisite errata before deployment.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2024:4873 for Red Hat build of Apicurio Registry 2.6.1 GA container images. The update fixed issues in webpack-dev-middleware, Express, Jetty, jose4j, and Quarkus Core, including CVE-2024-2700 configuration-property leakage.
Red Hat issued Important-rated RHSA-2024:4520 for Migration Toolkit for Containers 1.7.16 on RHEL 8 x86_64. The update remediated vulnerabilities in webpack-dev-middleware, Go components, and Envoy, including file-disclosure, memory/CPU exhaustion, and certificate-processing issues.
Red Hat issued Important-rated RHSA-2024:4460 for Red Hat Data Grid 8, upgrading version 8.4.8 to 8.5.0. The update fixed CVE-2024-29180, a webpack-dev-middleware file-disclosure flaw, and CVE-2024-29025, a Netty HTTP uncontrolled-resource-allocation issue.
Red Hat issued Important-rated RHSA-2024:2941 for Red Hat Advanced Cluster Security 4.4.2. The release addressed HTTP/2 CONTINUATION-frame denial of service and webpack-dev-middleware file-disclosure issues, while also fixing Collector crashes, Scanner false positives, network-graph failures, and stale-alert update problems.
Red Hat issued Moderate-severity advisory RHSA-2024:2705 for Red Hat build of Quarkus 3.2.12. It fixed CVE-2024-2700 in Quarkus Core and CVE-2024-29025 in Netty's netty-codec-http.
Red Hat issued RHSA-2024:2106 for Red Hat build of Quarkus 3.8.4, rated Moderate. The update remediated CVE-2024-2700, which could embed local Quarkus configuration properties in applications, and CVE-2024-29025, a Netty HTTP resource-exhaustion flaw.
Red Hat issued Important-rated RHSA-2024:1662 for Red Hat build of Quarkus 3.2.11. The update fixed seven CVEs, including SQL injection in the PostgreSQL JDBC driver, Quarkus Kubernetes annotation disclosure, RESTEasy Reactive denial of service, Apache Commons Compress denial-of-service flaws, and Vert.x memory leaks.
Red Hat issued Moderate-rated RHSA-2023:5441 for Red Hat Integration Camel for Spring Boot 4.0.0. The update fixed eight vulnerabilities in Apache Batik, Ivy, Jetty, Johnzon, and Netty, including SSRF, XXE, denial-of-service, cookie-disclosure, and HTTP/1 Content-Length validation issues.
Red Hat issued Important-rated RHSA-2023:5165 for Red Hat AMQ Streams 2.5.0 on RHEL 8. The update remediated 15 vulnerabilities, including SnakeYAML and Scala deserialization flaws, Netty, Jetty, Okio, and snappy-java denial-of-service issues, and insecure temporary-file creation vulnerabilities.
Red Hat documented CVE-2024-1300, in which Vert.x TLS TCP servers with SNI enabled retain default-certificate SSL contexts for arbitrary unknown SNI hostnames. An unauthenticated attacker could send repeated TLS ClientHello messages with distinct SNI values to exhaust JVM memory and cause denial of service; affected vertx-core versions span 4.3.4 through 4.5.2.
Red Hat published security advisory RHSA-2024:3527. The available reference does not provide a synopsis or technical details about affected products, vulnerabilities, or fixes.
Red Hat addressed CVE-2024-1023, a regression in Vert.x 4.4 and early 4.5 releases that can leak memory through Netty FastThreadLocal structures when the HTTP client connects to different hosts. The issue affected vertx-core 4.4.5, 4.4.6, 4.5.0, and 4.5.1 and was remediated through advisories for products including Quarkus, Cryostat, Service Registry, AMQ Streams, MTA, and Camel for Spring Boot.
Red Hat documented CVE-2023-34462, in which Netty's SniHandler could allocate up to 16 MB per TLS channel from attacker-crafted ClientHello data, enabling heap-memory exhaustion and denial of service. Netty fixed the flaw in 4.1.94.Final, and Red Hat issued updates for products including AMQ Streams, Data Grid, JBoss EAP, Quarkus, Service Registry, Cryostat, and Camel components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.