7.5
CVE-2026-17615
- EPSS 0.28%
- Veröffentlicht 31.08.2026 16:15:01
- Zuletzt bearbeitet 02.10.2026 05:16:37
- Erkennungen
Resteasy-core: resteasy sourceprovider remote unauthenticated file read
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6
Default Statusaffected
Version
26.6.7-3
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6
Default Statusaffected
Version
26.6-20
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6
Default Statusaffected
Version
26.6-20
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Keycloak 26.6.7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 9
Default Statusaffected
Version
0:3.0.26-20.el9_8
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Apache Camel 4 for Quarkus 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Apicurio Registry 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat build of Debezium 3
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Enterprise Linux 8
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat Fuse 7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt
Red Hat JBoss Enterprise Application Platform 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat JBoss Enterprise Application Platform Expansion Pack
Default Statusaffected
HerstellerRed Hat
≫
Produkt
Red Hat Satellite 6
Default Statusunaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.2 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://access.redhat.com/security/cve/CVE-2026-17615
https://bugzilla.redhat.com/show_bug.cgi?id=2507635
https://access.redhat.com/errata/RHSA-2026:63302
https://access.redhat.com/errata/RHSA-2026:62515
https://access.redhat.com/errata/RHSA-2026:62555
https://access.redhat.com/errata/RHSA-2026:68277
https://access.redhat.com/errata/RHSA-2026:68278
https://access.redhat.com/errata/RHSA-2026:72424