{"id":"CVE-2026-89059","title":"A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count","summary":"A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-409"],"vendor":"Red Hat","product":"RESTEasy","affected":["RESTEasy < 6.2.19.Final","RESTEasy >= 7.0.0.Alpha1 < 7.0.5.Final","resteasy-core (all versions)","resteasy-core (all versions)","resteasy-core (all versions)","resteasy-core (all versions)","rhbk/keycloak-rhel9-operator (all versions)","resteasy-core (all versions)","redhat-pki:10/redhat-pki (all versions)","redhat-pki (all versions)","dogtag-pki (all versions)","pki-core:10.6/pki-core (all versions)","jackson-jaxrs-providers (all versions)","pki-core (all versions)","resteasy-core (all versions)","resteasy-jaxrs (all versions)","jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 (all versions)","jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 (all versions)","jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 (all versions)","resteasy-jaxrs (all versions)","resteasy-core (all versions)","resteasy-core (all versions)","candlepin (all versions)","resteasy-jaxrs (all versions)"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:06:08.407","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89059","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-89059","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519756","label":"secalert@redhat.com"},{"url":"https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb","label":"secalert@redhat.com"},{"url":"https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519756","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89059.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89059"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89059"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"epss":0.00562,"epssPercentile":0.45264,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-18T15:13:24.737882Z"},"ingestedAt":"2026-09-18T07:37:23.437Z","slug":"CVE-2026-89059","body":"## Overview\n\nA flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat build of Quarkus, Red Hat Certificate System 10, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89059.json)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":206904,"id":"CVE-2026-89059","ts":1789746336816,"field":"exploit_available","old":"false","new":"true"}]}