Red Hat RESTEasy: XML external entity
High7.5CVE-2026-17615 · Published Aug 31, 2026 · updated Sep 16, 2026
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat build of Apache Camel 4 for Quarkus 3 Product | all versions | No fix yet |
| Red Hat build of Apicurio Registry 3 Product | all versions | No fix yet |
| Red Hat build of Debezium 3 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-611
- www.cve.org/CVERecord?id=CVE-2026-17615
- nvd.nist.gov/vuln/detail/CVE-2026-17615
- access.redhat.com/errata/RHSA-2026:62515
- access.redhat.com/errata/RHSA-2026:62555
- access.redhat.com/errata/RHSA-2026:63302
- access.redhat.com/errata/RHSA-2026:68277
- access.redhat.com/errata/RHSA-2026:68278
- access.redhat.com/security/cve/CVE-2026-17615
- bugzilla.redhat.com/show_bug.cgi?id=2507635
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Red Hat popt. This vulnerability: memory corruption | Low2.5 | No fix yet |
| Aug 31 | Red Hat WebKitGTK: memory corruption | High8.8 | No fix yet |
| Aug 31 | Red Hat GDB: out-of-bounds write | High7.0 | No fix yet |
| Aug 31 | Red Hat build of Quarkus: denial of service | High7.5 | No fix yet |
| Aug 31 | Red Hat Qute template engine: template injection | High8.8 | 3.27.5.SP1+1 more |
| Aug 31 | Red Hat Enterprise Linux 10: resource exhaustion | High7.5 | No fix yet |