Skip to content
red-hatCVE-2026-89058

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with...

High7.4CVE-2026-89058 · Published Sep 18, 2026 · updated Sep 19, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Red Hat Build of Keycloak
Vendor
all versionsNo fix yet
all versionsNo fix yet
Red Hat Certificate System 10
Vendor
all versionsNo fix yet
Red Hat Certificate System 11
Vendor
all versionsNo fix yet
Red Hat Enterprise Linux 10
Vendor
all versionsNo fix yet
Red Hat Enterprise Linux 8
Vendor
all versionsNo fix yet
Red Hat Enterprise Linux 9
Vendor
all versionsNo fix yet
Red Hat build of Apache Camel 4 for Quarkus 3
Vendor
all versionsNo fix yet
Red Hat build of Apicurio Registry 3
Vendor
all versionsNo fix yet
Red Hat build of Debezium 3
Vendor
all versionsNo fix yet
Red Hat build of Quarkus
Vendor
all versionsNo fix yet
Red Hat, Inc.: CVE records (CNA)
Vendor
< 6.2.19.Final6.2.19.Final
>= 7.0.0.Alpha1, < 7.0.5.Final7.0.5.Final
Details and references

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Severity from
no source yet
Weakness
CWE-942

More red-hat advisories

All
DateAdvisory
Sep 17A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker...
CVE-2026-90997High7.4fixed in Keycloak 26.7.4
Sep 17A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing.
CVE-2026-76781Medium5.5no fix yet
Sep 18A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count.
CVE-2026-89059High7.5fixed in Red Hat, Inc.: CVE records (CNA) 6.2.19.Final, Red Hat, Inc.: CVE records (CNA) 7.0.5.Final
Sep 18A flaw was found in Netty's `netty-handler-ssl-ocsp` component.
CVE-2026-93493Medium5.9no fix yet
Sep 18A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte.
CVE-2026-93494High7.5no fix yet
Sep 17A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application...
CVE-2026-87742High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.