Visit NES for Quarkus Home Page

Quarkus 2.16.x Release Notes

1 version

Comprehensive release notes and changelog for Quarkus 2.16.x, including security patches, bug fixes, and feature updates across all supported versions.

Jul 9, 2026
Latest: 2.16.13
5 Patched Vulnerabilities
VEX Statements

July 2026

Full Version:
2.16.12-quarkus-2.16.13

Notes

  • This release originates from the open‑source Quarkus repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds, together with the backported security fixes listed below.

Bug Fixes

  • Leak of local build-time configuration (environment variables and system properties) into recorded runtime defaults (CVE-2024-2700).
  • Authentication bypass via the default WebAuthn callback endpoint being registered even for applications with custom endpoints (CVE-2024-12225).
  • Denial of service from leaked response buffers in RESTEasy Classic when client connections end early (CVE-2025-1634).
  • Denial of service from worker threads blocking indefinitely on a full write queue in RESTEasy Reactive (CVE-2025-66560).
  • Authorization bypass via matrix parameters in HTTP path-based security policy matching (CVE-2026-39852).

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.