CVE-2026-40180 | quarkiverse quarkus-openapi-generator up to 2.15.x ZIP ApicurioCodegenWrapper.java unzip path traversal (GHSA-jx2w-vp7f-456q)
A vulnerability was found in quarkiverse quarkus-openapi-generator up to 2.15.x. It has been classified as critical. The impacted element is the function unzip of the file ApicurioCodegenWrapper.java of the component ZIP Handler. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-40180. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.