{"id":"CVE-2026-17615","title":"A flaw was found in RESTEasy's SourceProvider","summary":"A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-611"],"vendor":"Red Hat","product":"keycloak-rhel9-container","affected":["keycloak-rhel9-container (all versions)","keycloak-rhel9-operator-bundle-container (all versions)","keycloak-rhel9-operator-container (all versions)","keycloak/rhbk-rhel9-operator","resteasy-core","rhbk/keycloak-rhel9-operator","rhbk-keycloak-rhel9-operator/rhbk-keycloak-rhel9-operator","rhbk-rhel9-operator/rhbk-rhel9-operator","resteasy-core (all versions)","resteasy-core (all versions)","resteasy-core (all versions)","pki-core:10.6/resteasy (all versions)","pki-deps:10.6/resteasy (all versions)","resteasy (all versions)","resteasy-core","resteasy-core (all versions)","resteasy-core (all versions)","candlepin"],"patched":["build_of_keycloak 26.6.7"],"published":"2026-08-31","updated":"2026-09-16","sourceUpdated":"2026-09-16T19:17:08.403","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17615","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:62515","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:62555","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:63302","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68277","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:68278","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-17615","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507635","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-17615.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-17615"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17615"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00346,"epssPercentile":0.25419,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-31T17:09:02.820161Z"},"ingestedAt":"2026-09-14T08:56:10.922Z","slug":"CVE-2026-17615","body":"## Overview\n\nA flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 8, … · no fix planned: Red Hat Enterprise Linux 8, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-17615.json)\n- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}