Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)
Published Sep 18, 2026
7.5
HIGHCVSS 3.1
EPSS 0.79%
Description
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
Affected products
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
-
Affected
- ≥ 0, < 6.2.19.Final
- ≥ 7.0.0.Alpha1, < 7.0.5.Final
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | affected | |
| Red Hat | Red Hat Certificate System 10 | affected | |
| Red Hat | Red Hat Certificate System 11 | affected | |
| Red Hat | Red Hat Enterprise Linux 10 | affected | |
| Red Hat | Red Hat Enterprise Linux 8 | affected | |
| Red Hat | Red Hat Enterprise Linux 9 | affected | |
| Red Hat | Red Hat Fuse 7 | affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected | |
| Red Hat | Red Hat Satellite 6 | affected | |
| Red Hat | Red Hat Single Sign-On 7 | affected | |
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | affected | |
| Red Hat | Red Hat build of Apicurio Registry 3 | affected | |
| Red Hat | Red Hat build of Debezium 3 | affected | |
| Red Hat | Red Hat build of Quarkus | affected | |
| Red Hat | n/a | unaffected | Affected
|
No data.
No data.
Red Hat Build of Keycloak
resteasy-core
Affected
Red Hat Build of Keycloak
rhbk/keycloak-rhel9-operator
Affected
Red Hat Certificate System 10
redhat-pki:10/redhat-pki
Affected
Red Hat Certificate System 11
redhat-pki
Affected
Red Hat Enterprise Linux 10
dogtag-pki
Affected
Red Hat Enterprise Linux 8
pki-core:10.6/pki-core
Affected
Red Hat Enterprise Linux 9
jackson-jaxrs-providers
Affected
Red Hat Enterprise Linux 9
pki-core
Affected
Red Hat Fuse 7
resteasy-core
Will not fix
Red Hat Fuse 7
resteasy-jaxrs
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
Will not fix
Red Hat JBoss Enterprise Application Platform 7
resteasy-jaxrs
Will not fix
Red Hat JBoss Enterprise Application Platform 8
resteasy-core
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
resteasy-core
Affected
Red Hat Satellite 6
candlepin
Affected
Red Hat Single Sign-On 7
resteasy-jaxrs
Affected
Red Hat build of Apache Camel 4 for Quarkus 3
resteasy-core
Affected
Red Hat build of Apicurio Registry 3
resteasy-core
Affected
Red Hat build of Debezium 3
resteasy-core
Affected
Red Hat build of Quarkus
resteasy-core
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Keycloak | resteasy-core | Affected | n/a |
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Affected | n/a |
| Red Hat Certificate System 10 | redhat-pki:10/redhat-pki | Affected | n/a |
| Red Hat Certificate System 11 | redhat-pki | Affected | n/a |
| Red Hat Enterprise Linux 10 | dogtag-pki | Affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/pki-core | Affected | n/a |
| Red Hat Enterprise Linux 9 | jackson-jaxrs-providers | Affected | n/a |
| Red Hat Enterprise Linux 9 | pki-core | Affected | n/a |
| Red Hat Fuse 7 | resteasy-core | Will not fix | n/a |
| Red Hat Fuse 7 | resteasy-jaxrs | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | resteasy-jaxrs | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | resteasy-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | resteasy-core | Affected | n/a |
| Red Hat Satellite 6 | candlepin | Affected | n/a |
| Red Hat Single Sign-On 7 | resteasy-jaxrs | Affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | resteasy-core | Affected | n/a |
| Red Hat build of Apicurio Registry 3 | resteasy-core | Affected | n/a |
| Red Hat build of Debezium 3 | resteasy-core | Affected | n/a |
| Red Hat build of Quarkus | resteasy-core | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-89059 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2519756 exploitissue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82735 Advisory
- https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb
- https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-89059
- https://www.cve.org/CVERecord?id=CVE-2026-89059
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-89059 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2519756 | exploitissue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-82735 | Advisory | |
| https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb | ||
| https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2 | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-89059 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-89059 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data