Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89059

Опубликовано: 17 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3resteasy-coreAffected
Red Hat build of Apicurio Registry 3resteasy-coreAffected
Red Hat build of Debezium 3resteasy-coreAffected
Red Hat Build of Keycloakresteasy-coreAffected
Red Hat Build of Keycloakrhbk/keycloak-rhel9-operatorAffected
Red Hat build of Quarkusresteasy-coreAffected
Red Hat Certificate System 10redhat-pki:10/redhat-pkiAffected
Red Hat Certificate System 11redhat-pkiAffected
Red Hat Enterprise Linux 10dogtag-pkiAffected
Red Hat Enterprise Linux 8pki-core:10.6/pki-coreAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2519756resteasy-core: RESTEasy: IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS)

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 дня назад

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

CVSS3: 7.5
nvd
5 дней назад

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

CVSS3: 7.5
debian
5 дней назад

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacke ...

7.5 High

CVSS3