---
id: CVE-2026-89059
title: >-
  A flaw was found in RESTEasy's IIOImageProvider, which decodes
  attacker-supplied image request bodies without enforcing any limit on the
  declared image dimensions or pixel count
summary: >-
  A flaw was found in RESTEasy's IIOImageProvider, which decodes
  attacker-supplied image request bodies without enforcing any limit on the
  declared image dimensions or pixel count. A remote, unauthenticated attacker
  can send a small crafte…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-409
vendor: Red Hat
product: RESTEasy
affected:
  - RESTEasy < 6.2.19.Final
  - RESTEasy >= 7.0.0.Alpha1 < 7.0.5.Final
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - resteasy-core (all versions)
  - 'redhat-pki:10/redhat-pki (all versions)'
  - redhat-pki (all versions)
  - dogtag-pki (all versions)
  - 'pki-core:10.6/pki-core (all versions)'
  - jackson-jaxrs-providers (all versions)
  - pki-core (all versions)
  - resteasy-core (all versions)
  - resteasy-jaxrs (all versions)
  - jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 (all versions)
  - jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 (all versions)
  - jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 (all versions)
  - resteasy-jaxrs (all versions)
  - resteasy-core (all versions)
  - resteasy-core (all versions)
  - candlepin (all versions)
  - resteasy-jaxrs (all versions)
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:06:08.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89059'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89059'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2519756'
    label: secalert@redhat.com
  - url: >-
      https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb
    label: secalert@redhat.com
  - url: >-
      https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2519756'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89059.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89059'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89059'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.00562
epssPercentile: 0.45516
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T15:13:24.737882Z'
ingestedAt: '2026-09-18T07:37:23.437Z'
---

## Overview

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat build of Quarkus, Red Hat Certificate System 10, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89059.json)
