Back

HIGH

Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)

Published Sep 18, 2026

Description

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 18, 2026
Updated Sep 18, 2026
Reserved Sep 10, 2026

CISA Vulnrichment

Updated Sep 18, 2026

NVD

Status Awaiting Analysis
Modified Sep 18, 2026

Red Hat

Severity Important
Public date Sep 17, 2026
Bugzilla 2519756

ENISA EUVD

Assigner redhat
Published Sep 18, 2026
Updated Sep 18, 2026

GitHub

No data