Skip to content
Red HatCVE-2026-89059

Red Hat RESTEasy: denial of service

High7.5CVE-2026-89059 · Published Sep 18, 2026

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Build of Keycloak
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Certificate System 10
Product
all versionsNo fix yet
Red Hat Certificate System 11
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat build of Apache Camel 4 for Quarkus 3
Product
all versionsNo fix yet
Red Hat build of Apicurio Registry 3
Product
all versionsNo fix yet
Red Hat build of Debezium 3
Product
all versionsNo fix yet
Red Hat build of Quarkus
Product
all versionsNo fix yet
Red Hat, Inc.: CVE records (CNA)
Product
< 6.2.19.Final6.2.19.Final
>= 7.0.0.Alpha1, < 7.0.5.Final7.0.5.Final
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat OpenShift Container Platform 4: server-side request forgery
Critical9.3Sep 18
Red Hat Netty: request smuggling
Medium6.5Sep 18
Red Hat Netty: request smuggling
Medium6.5Sep 18
A flaw was found in cockpit-files
Medium6.1Sep 18
Red Hat cockpit-files. This vulnerability: race condition
Medium6.0Sep 18
Red Hat cockpit-files: race condition
Medium6.0Sep 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.