VulnSea

resteasy vulnerabilities

CVEs whose affected-version data names the resteasy package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-89059High· 7.5PoC
4d ago

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafte…

MidnightRed Hat · RESTEasyEPSS 0.56%via NVD
CVE-2026-89058High· 7.4PoC
4d ago

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. Thi…

MidnightRed Hat · RESTEasyEPSS 0.42%via NVD
CVE-2026-17615High· 7.5
3w ago

A flaw was found in RESTEasy's SourceProvider

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD
CVE-2026-81624High· 7.5
3w ago

Undertow is a flexible performant web server used in JBoss EAP and WildFly

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot …

TwilightRed Hat · undertow-coreEPSS 0.33%via NVD
CVE-2026-5680High· 7.5
3w ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDef…

TwilightRed Hat · undertow-coreEPSS 0.40%via NVD
resteasy vulnerabilities (CVEs) · VulnSea