rootpwn

high · CVSS v3 7.5 · EPSS 0.00556

CVE-2026-89059

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing …

Description

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Scores

Severity
high
CVSS v2
4.3
CVSS v3
7.5
CVSS v4
EPSS
0.00556

← All CVEs