A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-409"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89059.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "6.2.19.Final"
},
{
"introduced": "7.0.0.Alpha1"
},
{
"fixed": "7.0.5.Final"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89059.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "72818372968371405491439509507717823279",
"length": 202
},
"id": "CVE-2026-89059-410fbef9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
"target": {
"file": "resteasy-core/src/main/java/org/jboss/resteasy/plugins/providers/IIOImageProviderHelper.java",
"function": "readImage"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"97728258058544816004957738135948627883",
"277225259626050223963754197824424472281",
"104861131074000344537245127811394803876",
"105521377887849960965723874029594410558",
"98408534695236061767092211770526096831",
"219477713647064125439334731062287740678",
"330610207587412655921549031309798774408",
"333401632531303340302141094198439648043",
"8872333199681622956174137406762604675",
"56696934646108850776397078089572467826",
"119590764735634794177642404618353474056",
"167579054640525597957525344699869356036",
"203291498901860310198084804752524711764",
"20336738881372880353672519613634170936",
"158259341804675824510343583607171583934",
"43534959923489055825468574418775418576",
"205429568788342353740177262112033050375",
"238589175286512962030925275621620547394",
"256088021166405780217470682181013660508"
],
"threshold": 0.9
},
"id": "CVE-2026-89059-4dd4b9c7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
"target": {
"file": "resteasy-core/src/main/java/org/jboss/resteasy/plugins/providers/IIOImageProviderHelper.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"43488508021642552777434816334393166452",
"130083499163662666249127700728448729065",
"223189749652368537677359447221427017532",
"184890472307517486039236504680324624312",
"271072172263586034189317986436488448459",
"54233657099444375447921120266740173582"
],
"threshold": 0.9
},
"id": "CVE-2026-89059-8194da42",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
"target": {
"file": "resteasy-core-spi/src/main/java/org/jboss/resteasy/resteasy_jaxrs/i18n/Messages.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"246302272464557232268089755158194418901",
"139364369482902646250372899590878041623",
"116314609309993823143965014973361366937"
],
"threshold": 0.9
},
"id": "CVE-2026-89059-9e2ae012",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb",
"target": {
"file": "resteasy-core-spi/src/main/java/org/jboss/resteasy/spi/config/Options.java"
}
}
]
"2026-09-20T14:16:35Z"