Quarkus 3.27.5 released - LTS maintenance release

Today, we released Quarkus 3.27.5, our next maintenance release for the 3.27 LTS stream.

This release contains bugfixes, documentation updates, and security fixes.

It should be a safe upgrade for anyone already using 3.27.

Security fixes

This release fixes the following CVEs:

Quarkus and direct dependencies

  • CVE-2026-15075 - Eclipse Vert.x: DefaultRedirectHandler cross-origin header propagation

  • CVE-2026-15076 - Eclipse Vert.x: WebClientSession cross-domain cookie injection

  • CVE-2026-53712 - OnGres SCRAM client: Authentication downgrade

  • CVE-2026-59888 - Jackson-databind: @JsonIgnore bypass with PropertyNamingStrategy on Java Records

  • CVE-2026-59889 - Jackson-databind: @JsonView bypass for @JsonUnwrapped properties during deserialization

  • CVE-2026-8484 - Jansi: Heap-based buffer overflow in JNI ioctl() wrapper

  • CVE-2026-55405 - LangChain4j: SQL injection in embedding store metadata filter

Netty

This release upgrades Netty to 4.1.136.Final, which fixes numerous security vulnerabilities including:

For the full list, see the Netty 4.1.136.Final release announcement.

Update

To update to Quarkus 3.27, we recommend updating to the latest version of the Quarkus CLI and run:

quarkus update --stream=3.27

Note that quarkus update can update your applications from any version of Quarkus (including 2.x) to Quarkus 3.27.

Full changelog

Come Join Us

We value your feedback a lot so please report bugs, ask for improvements…​ Let’s build something great together!

If you are a Quarkus user or just curious, don’t be shy and join our welcoming community: