CVE-2026-89059

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Published
September 18, 2026 8:17 AM
Last Modified
September 18, 2026 8:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-409

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.