Quarkus 3.27.5 released - LTS maintenance release

Today, we released Quarkus 3.27.5, our next maintenance release for the 3.27 LTS stream.

This release contains bugfixes, documentation updates, and security fixes.

3.27 をすでに使用している方にとっては、安全にアップグレードできます。

Security fixes

This release fixes the following CVEs:

Quarkus and direct dependencies

  • CVE-2026-15075 - Eclipse Vert.x: DefaultRedirectHandler cross-origin header propagation

  • CVE-2026-15076 - Eclipse Vert.x: WebClientSession cross-domain cookie injection

  • CVE-2026-53712 - OnGres SCRAM client: Authentication downgrade

  • CVE-2026-59888 - Jackson-databind: @JsonIgnore bypass with PropertyNamingStrategy on Java Records

  • CVE-2026-59889 - Jackson-databind: @JsonView bypass for @JsonUnwrapped properties during deserialization

  • CVE-2026-8484 - Jansi: Heap-based buffer overflow in JNI ioctl() wrapper

  • CVE-2026-55405 - LangChain4j: SQL injection in embedding store metadata filter

Netty

This release upgrades Netty to 4.1.136.Final, which fixes numerous security vulnerabilities including:

For the full list, see the Netty 4.1.136.Final release announcement.

Update

Quarkus 3.27 に更新するには、Quarkus CLI の最新バージョンに更新してから、以下を実行することをお勧めします。

quarkus update --stream=3.27

quarkus update は、Quarkus の任意のバージョン (2.x を含む) から Quarkus 3.27 にアプリケーションを更新できます。

完全な変更履歴

参加のお誘い

私達は皆様からのフィードバックに重きを置いています。バグ報告、改善要望を是非お願いします。一緒に素晴らしいものを作り上げていきましょう!

Quarkusユーザーの場合でも、単に興味を持っているだけの場合でも、恥ずかしがらずにコミュニティに参加して下さい!: