Synced 16 Jun 2026 15:24 UTC Account

Is Quarkus 3.23.4 patched?

Red Hat · cycle 3.23 · end of life · Official site ↗
3.23.440/100End of life

Current stable (3.36.2): 100/100

Minimum safe version3.27.3.1

3.23.4 has 1 open critical-or-high vulnerability. Run 3.27.3.1 or later to clear it. See what 3.27.3.1 fixes →

Health score40/100
Open issues2
Exploited now0
Cycle 3.23 EOL2025-06-25
Latest release3.36.2

Summary iPlain-English security status for Quarkus 3.23.4, built from its CVEs, active-exploitation data, end-of-life date and latest release.

Quarkus 3.23.4 is part of the 3.23 release line. 2 known vulnerabilities affect it. The minimum safe version is 3.27.3.1 — upgrade to it or later to clear the open critical/high issues. The 3.23 line reached end-of-life on 2025-06-25, so it no longer receives security patches. The latest supported Quarkus release is 3.36.2.

Known issues affecting 3.23.4

Exploited first, then by exploitation probability.

CVE-2025-66560 MEDIUM EPSS 0% → fixed in 3.31.0 CVE-2026-39852 HIGH EPSS 0% → fixed in 3.35.2

Frequently asked

Is Quarkus 3.23.4 patched?

Quarkus 3.23.4 is end-of-life and no longer receives security patches. Move to 3.36.2.

What version should I upgrade Quarkus 3.23.4 to?

Upgrade Quarkus 3.23.4 to at least 3.27.3.1 to clear its 1 open critical-or-high vulnerability.

When does Quarkus 3.23 reach end-of-life?

Quarkus 3.23 reached end-of-life on 2025-06-25 and no longer receives security patches.

What is the latest version of Quarkus?

The latest supported Quarkus release is 3.36.2.

Is Quarkus 3.23.4 still receiving security updates?

No — Quarkus 3.23.4 is on the 3.23 line, which reached end-of-life on 2025-06-25 and no longer receives security updates. Upgrade to 3.36.2 or later to stay supported.

Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Red Hat's official advisory before you patch or upgrade — Quarkus official site ↗