---
id: CVE-2026-17615
title: A flaw was found in RESTEasy's SourceProvider
summary: >-
  A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an
  unauthenticated attacker to perform an unauthenticated remote file read. By
  sending a specially crafted XML body with a DOCTYPE declaration referencing
  external …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-611
vendor: Red Hat
product: keycloak-rhel9-container
affected:
  - keycloak-rhel9-container (all versions)
  - keycloak-rhel9-operator-bundle-container (all versions)
  - keycloak-rhel9-operator-container (all versions)
  - keycloak/rhbk-rhel9-operator
  - resteasy-core
  - rhbk/keycloak-rhel9-operator
  - rhbk-keycloak-rhel9-operator/rhbk-keycloak-rhel9-operator
  - rhbk-rhel9-operator/rhbk-rhel9-operator
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - 'pki-core:10.6/resteasy (all versions)'
  - 'pki-deps:10.6/resteasy (all versions)'
  - resteasy (all versions)
  - resteasy-core
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - candlepin
patched:
  - build_of_keycloak 26.6.7
published: '2026-08-31'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:08.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17615'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:62515'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:62555'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:63302'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:68278'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-17615'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507635'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-17615.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-17615'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17615'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00346
epssPercentile: 0.25419
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-31T17:09:02.820161Z'
ingestedAt: '2026-09-14T08:56:10.922Z'
---

## Overview

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:68278** · Red Hat · fixed in: Red Hat build of Keycloak 26.6.7 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68278)
- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 8, … · no fix planned: Red Hat Enterprise Linux 8, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-17615.json)
- **RHSA-2026:68277** · Red Hat · fixed in: Red Hat build of Keycloak 26.6 · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68277)
