Resteasy-core: resteasy sourceprovider remote unauthenticated file read
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.3%
probabilidad de explotación
0.3%top 72% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
Red Hat · Red Hat build of Apache Camel 4 for Quarkus 3Red Hat · Red Hat build of Apicurio Registry 3Red Hat · Red Hat build of Debezium 3Red Hat · Red Hat build of Keycloak 26.6Red Hat · Red Hat build of Keycloak 26.6.7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Fuse 7Red Hat · Red Hat JBoss Enterprise Application Platform 8Red Hat · Red Hat JBoss Enterprise Application Platform Expansion PackRed Hat · Red Hat Satellite 6Referencias
https://access.redhat.com/errata/RHSA-2026:62515https://access.redhat.com/errata/RHSA-2026:62555https://access.redhat.com/errata/RHSA-2026:63302https://access.redhat.com/errata/RHSA-2026:68277https://access.redhat.com/errata/RHSA-2026:68278https://access.redhat.com/security/cve/CVE-2026-17615https://bugzilla.redhat.com/show_bug.cgi?id=2507635