resteasy: Unsafe unmarshalling in YamlProvider allows code execution
Published Jan 25, 2018
8.1
HIGHCVSS 3.0
EPSS 1.31%
Description
It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.
Affected products
-
- Version after 3.0.22StatusaffectedConstraints-
- Version after 3.1.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Red Hat, Inc. | Resteasy | n/a |
|
No data.
Red Hat BPM Suite 6
resteasy
Not affected
Red Hat Enterprise Linux 7
resteasy-base
Not affected
Red Hat Enterprise Linux 8
resteasy
Not affected
Red Hat JBoss BRMS 6
resteasy
Not affected
Red Hat JBoss Data Grid 6
resteasy
Out of support scope
Red Hat JBoss Data Virtualization 6
resteasy
Out of support scope
Red Hat JBoss Enterprise Application Platform 5
resteasy
Will not fix
Red Hat JBoss Enterprise Application Platform 6
resteasy
Will not fix
Red Hat JBoss Enterprise Application Platform 7
resteasy
Will not fix
Red Hat JBoss Fuse 6
resteasy
Not affected
Red Hat JBoss Fuse Service Works 6
resteasy
Out of support scope
Red Hat JBoss Operations Network 3
resteasy
Not affected
Red Hat JBoss Portal 6
resteasy
Out of support scope
Red Hat JBoss SOA Platform 5
resteasy
Out of support scope
Red Hat Mobile Application Platform 4
millicore
Not affected
Red Hat Satellite 6
resteasy
Will not fix
Red Hat Single Sign-On 7
resteasy
Will not fix
Red Hat Subscription Asset Manager
resteasy
Will not fix
Red Hat Virtualization 4
eap7-resteasy-yaml-provider
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat BPM Suite 6 | resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 7 | resteasy-base | Not affected | n/a |
| Red Hat Enterprise Linux 8 | resteasy | Not affected | n/a |
| Red Hat JBoss BRMS 6 | resteasy | Not affected | n/a |
| Red Hat JBoss Data Grid 6 | resteasy | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | resteasy | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | resteasy | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | resteasy | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | resteasy | Will not fix | n/a |
| Red Hat JBoss Fuse 6 | resteasy | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | resteasy | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | resteasy | Not affected | n/a |
| Red Hat JBoss Portal 6 | resteasy | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | resteasy | Out of support scope | n/a |
| Red Hat Mobile Application Platform 4 | millicore | Not affected | n/a |
| Red Hat Satellite 6 | resteasy | Will not fix | n/a |
| Red Hat Single Sign-On 7 | resteasy | Will not fix | n/a |
| Red Hat Subscription Asset Manager | resteasy | Will not fix | n/a |
| Red Hat Virtualization 4 | eap7-resteasy-yaml-provider | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affects applications which have the YamlProvider explicitly enabled by adding or appending a file with the name 'META-INF/services/javax.ws.rs.ext.Providers' to your WAR, or JAR with the contents 'org.jboss.resteasy.plugins.providers.YamlProvider' resteasy-base as shipped in Red Hat Enterprise Linux 7 does not include YamlProvider. Red Hat Subscription Asset Manager version 1 is now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. This issue affects the versions of resteasy as shipped with Red Hat Satellite version 6, however Satellite version 6 does not use the affected functionality. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
If the YamlProvider is enabled it's recommended to add authentication, and authorization to the endpoint expecting Yaml content to prevent exploitation of this vulnerability.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.31% (0.01311) | 69.65th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.30% (0.01300) | 69.17th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.13% (0.00133) | 49.02th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.13% (0.00133) | 48.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00133) | 46.68th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.42% (0.00416) | 10.04th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2018-1051 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1535411 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1539175#c3
- https://github.com/advisories/GHSA-m2fv-3rqm-g7p5 Advisory
- https://github.com/resteasy/resteasy/pull/1555
- https://nvd.nist.gov/vuln/detail/CVE-2018-1051
- https://www.cve.org/CVERecord?id=CVE-2018-1051
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1051 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1535411 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1539175#c3 | ||
| https://github.com/advisories/GHSA-m2fv-3rqm-g7p5 | Advisory | |
| https://github.com/resteasy/resteasy/pull/1555 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-1051 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1051 |
Change history (0)
No recorded changes yet.