pki-deps:10.6/resteasy vulnerabilities
CVEs whose affected-version data names the pki-deps:10.6/resteasy package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-17615High· 7.5A flaw was found in RESTEasy's SourceProvider
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …
CVE-2026-81624High· 7.5Undertow is a flexible performant web server used in JBoss EAP and WildFly
Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …
CVE-2026-5680High· 7.5A flaw was found in Undertow
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDef…