← Back to CVE List
CVE-2026-89059NVD
Vulnerability Summary
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- Red Hat < 6.2.19.Final
- Red Hat >= 7.0.0.Alpha1 and < 7.0.5.Final
- Red Hat 6.2.19.Final
- Red Hat 7.0.5.Final