Quarkus 3.33.4 released - LTS maintenance release

Today, we released Quarkus 3.33.4, our next maintenance release for the 3.33 LTS stream.

This release contains bugfixes, documentation updates, and security fixes.

It should be a safe upgrade for anyone already using 3.33.

Security fixes

This release fixes the following CVEs:

Quarkus and direct dependencies

  • CVE-2026-89407 - FasterXML jackson-core: Denial of Service via quadratic regex backtracking in number validation

  • CVE-2026-89425 - FasterXML jackson-core: Denial of Service via unbounded error-token accumulation in UTF8DataInputJsonParser

  • CVE-2026-91777 - FasterXML jackson-databind: Denial of Service via quadratic-time forward-reference resolution for @JsonIdentityInfo

  • CVE-2026-91776 - FasterXML jackson-databind: Denial of Service via unbounded deserializer cache growth for unrecognized polymorphic type IDs

  • CVE-2026-84939 - Apache FreeMarker: Path traversal via malformed locale identifier

  • CVE-2026-94449 - Quarkus SmallRye Fault Tolerance: Memory leak in @ApplyGuard leads to Denial of Service

  • CVE-2026-82617 - Apache OpenNLP: Denial of Service via super-linear regex backtracking in built-in name finders

  • CVE-2026-68497 - Jackson-databind: Denial of Service via unbounded number parsing for Duration/XMLGregorianCalendar

  • CVE-2026-89059 - RESTEasy: Denial of Service via unbounded memory allocation in IIOImageProvider

  • CVE-2026-93432 - Quarkus Qute: Cross-Site Scripting via missing content-type propagation in {#eval} sub-templates

  • CVE-2026-59949 - LZ4 Java: Denial of Service via native XXHash crash on invalid byte array ranges

  • CVE-2026-59296 - Micrometer: Metrics injection/spoofing via unsanitized newline characters in StatsD and logging registries

  • CVE-2026-59295 - Micrometer: Denial of Service via unbounded memory leak in HttpAsyncClient instrumentation

Platform updates

This release includes Quarkus CXF 3.33.12.

  • Release notes for Quarkus CXF 3.33.10

  • Release notes for Quarkus CXF 3.33.11 and 3.33.12 are not yet published at the time of publishing this announcement

Update

To update to Quarkus 3.33, we recommend updating to the latest version of the Quarkus CLI and run:

quarkus update --stream=3.33

Note that quarkus update can update your applications from any version of Quarkus (including 2.x) to Quarkus 3.33.

Full changelog

Come Join Us

We value your feedback a lot so please report bugs, ask for improvements…​ Let’s build something great together!

If you are a Quarkus user or just curious, don’t be shy and join our welcoming community: