Today, we released Quarkus 3.27.6, our next maintenance release for the 3.27 LTS stream.This release contains bugfixes, documentation updates, and security fixes.It should be a safe upgrade for anyone already using 3.27.Please note that this is planned to be the last update to 3.27. Anybody still on 3.27 is advisedto look into upgrading to 3.33 or 3.40 (the next LTS) soon.Security fixesThis release fixes the following CVEs:Quarkus and direct dependenciesCVE-2026-89407 - FasterXML jackson-core: Denial of Service via quadratic regex backtracking in number validationCVE-2026-89425 - FasterXML jackson-core: Denial of Service via unbounded error-token accumulation in UTF8DataInputJsonParserCVE-2026-91777 - FasterXML jackson-databind: Denial of Service via quadratic-time forward-reference resolution for @JsonIdentityInfoCVE-2026-91776 - FasterXML jackson-databind: Denial of Service via unbounded deserializer cache growth for unrecognized polymorphic type IDsCVE-2026-84939 - Apache FreeMarker: Path traversal via malformed locale identifierCVE-2026-94449 - Quarkus SmallRye Fault Tolerance: Memory leak in @ApplyGuard leads to Denial of ServiceCVE-2026-82617 - Apache OpenNLP: Denial of Service via super-linear regex backtracking in built-in name findersCVE-2026-68497 - Jackson-databind: Denial of Service via unbounded number parsing for Duration/XMLGregorianCalendarCVE-2026-89059 - RESTEasy: Denial of Service via unbounded memory allocation in IIOImageProviderCVE-2026-93432 - Quarkus Qute: Cross-Site Scripting via missing content-type propagation in {#eval} sub-templatesCVE-2026-59949 - LZ4 Java: Denial of Service via native XXHash crash on invalid byte array rangesCVE-2026-61700 - MariaDB Connector/J: allowLocalInfile=false bypass via server-initiated LOCAL INFILE requestCVE-2026-55856 - MariaDB Connector/J: Cleartext password disclosure via MITM on the initial handshakeCVE-2026-55857 - MariaDB Connector/J: Cleartext transmission of credentials during PAM authenticationCVE-2026-55858 - MariaDB Connector/J: Data corruption via incorrect character set handling after a mid-session charset changePlatform updatesThis release includes Quarkus CXF 3.27.2.UpdateTo update to Quarkus 3.27, we recommend updating to the latest version of the Quarkus CLI and run:quarkus update --stream=3.27Note that quarkus update can update your applications from any version of Quarkus (including 2.x) to Quarkus 3.27.Full changelogYou can get the full changelog of 3.27.6 on GitHub.Come Join UsWe value your feedback a lot so please report bugs, ask for improvements…​ Let’s build something great together!If you are a Quarkus user or just curious, don’t be shy and join our welcoming community:provide feedback on GitHub;craft some code and push a PR;discuss with us on Zulip and on the mailing list;ask your questions on Stack Overflow.