7.5

CVE-2026-17615

Resteasy-core: resteasy sourceprovider remote unauthenticated file read

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6
Default Statusaffected
Version 26.6.7-3
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6
Default Statusaffected
Version 26.6-20
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6
Default Statusaffected
Version 26.6-20
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusaffected
Version 0:3.0.26-20.el9_8
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Apache Camel 4 for Quarkus 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Apicurio Registry 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Debezium 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Fuse 7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat JBoss Enterprise Application Platform 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat JBoss Enterprise Application Platform Expansion Pack
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Satellite 6
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.2
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://access.redhat.com/security/cve/CVE-2026-17615
https://bugzilla.redhat.com/show_bug.cgi?id=2507635
https://access.redhat.com/errata/RHSA-2026:63302
https://access.redhat.com/errata/RHSA-2026:62515
https://access.redhat.com/errata/RHSA-2026:62555
https://access.redhat.com/errata/RHSA-2026:68277
https://access.redhat.com/errata/RHSA-2026:68278
https://access.redhat.com/errata/RHSA-2026:72424