CVE-2026-89059

Source
https://cve.org/CVERecord?id=CVE-2026-89059
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89059.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89059
Aliases
  • GHSA-m4pc-7gc7-9vw2
Downstream
Published
2026-09-18T07:13:39Z
Modified
2026-09-20T14:16:35Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)
Details

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-409"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89059.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "fixed":  "6.2.19.Final"
                },
                {
                    "introduced":  "7.0.0.Alpha1"
                },
                {
                    "fixed":  "7.0.5.Final"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/resteasy/resteasy

Affected ranges

Type
GIT
Repo
https://github.com/resteasy/resteasy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Affected versions

3.*
3.0-beta-1
3.0-beta-2
3.0-beta-3
3.0-beta-4
3.0-beta-5
3.0-beta-6
3.0-rc-1
3.0.0.Final
3.0.1.Final
3.0.10.Final
3.0.13.Final
3.0.14.Final
3.0.15.Final
3.0.16.Final
3.0.2
3.0.4
3.0.5.Final
3.0.6.Final
3.0.7.Final
3.0.8.Final
3.0.9.Final
3.1.0.Beta1
3.1.0.Beta2
3.1.0.CR1
3.1.0.CR2
3.1.0.CR3
3.1.0.Final
3.1.1.Final
3.1.2.Final
3.1.3.Final
3.1.4.Final
4.*
4.0.0.Beta1
4.0.0.Beta2
4.0.0.Beta3
4.0.0.Beta4
4.0.0.Beta5
4.0.0.Beta6
4.0.0.Beta7
4.0.0.CR1
4.0.0.CR2
4.1.0.Final
4.2.0.Final
4.3.0.Final
4.4.0.CR1
4.4.0.Final
4.4.1.Final
4.4.2.Final
4.7.0.Beta1
4.7.0.Final
5.*
5.0.0.Alpha1
5.0.0.Beta1
5.0.0.Beta2
5.0.0.Beta3
5.0.0.Final
6.*
6.0.0.Beta1
6.0.0.Final
6.1.0.Alpha1
6.1.0.Beta1
6.1.0.Beta2
6.1.0.Beta3
6.1.0.Final
6.2.0.Beta1
6.2.0.Final
6.2.1.Final
6.2.2.Final
7.*
7.0.0.Alpha1
7.0.0.Alpha2
7.0.0.Alpha3
7.0.0.Alpha4
v7.*
v7.0.0.Beta1
v7.0.0.Beta2
v7.0.0.Beta3
v7.0.0.Beta4
v7.0.0.Beta5
v7.0.0.Final
v7.0.2.Final
v7.0.3.Final
v7.0.4.Final

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89059.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "72818372968371405491439509507717823279",
            "length":  202
        },
        "id":  "CVE-2026-89059-410fbef9",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
        "target":  {
            "file":  "resteasy-core/src/main/java/org/jboss/resteasy/plugins/providers/IIOImageProviderHelper.java",
            "function":  "readImage"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "97728258058544816004957738135948627883",
                "277225259626050223963754197824424472281",
                "104861131074000344537245127811394803876",
                "105521377887849960965723874029594410558",
                "98408534695236061767092211770526096831",
                "219477713647064125439334731062287740678",
                "330610207587412655921549031309798774408",
                "333401632531303340302141094198439648043",
                "8872333199681622956174137406762604675",
                "56696934646108850776397078089572467826",
                "119590764735634794177642404618353474056",
                "167579054640525597957525344699869356036",
                "203291498901860310198084804752524711764",
                "20336738881372880353672519613634170936",
                "158259341804675824510343583607171583934",
                "43534959923489055825468574418775418576",
                "205429568788342353740177262112033050375",
                "238589175286512962030925275621620547394",
                "256088021166405780217470682181013660508"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-89059-4dd4b9c7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
        "target":  {
            "file":  "resteasy-core/src/main/java/org/jboss/resteasy/plugins/providers/IIOImageProviderHelper.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "43488508021642552777434816334393166452",
                "130083499163662666249127700728448729065",
                "223189749652368537677359447221427017532",
                "184890472307517486039236504680324624312",
                "271072172263586034189317986436488448459",
                "54233657099444375447921120266740173582"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-89059-8194da42",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
        "target":  {
            "file":  "resteasy-core-spi/src/main/java/org/jboss/resteasy/resteasy_jaxrs/i18n/Messages.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "246302272464557232268089755158194418901",
                "139364369482902646250372899590878041623",
                "116314609309993823143965014973361366937"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-89059-9e2ae012",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
        "target":  {
            "file":  "resteasy-core-spi/src/main/java/org/jboss/resteasy/spi/config/Options.java"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:16:35Z"