UBUNTU-CVE-2026-17615

Source
https://ubuntu.com/security/CVE-2026-17615
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-17615
Upstream
  • CVE-2026-17615
Published
2026-09-03T00:00:00Z
Modified
2026-09-03T22:54:17.776606563Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.

References

Affected packages

Ubuntu:22.04:LTS
resteasy3.0

Package

Name
resteasy3.0
Purl
pkg:deb/ubuntu/resteasy3.0?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.26-2
3.0.26-3
3.0.26-3ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.26-3ubuntu0.1",
            "binary_name": "libresteasy3.0-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:24.04:LTS
resteasy3.0

Package

Name
resteasy3.0
Purl
pkg:deb/ubuntu/resteasy3.0?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.26-6
3.0.26-6ubuntu0.24.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.26-6ubuntu0.24.04.1",
            "binary_name": "libresteasy3.0-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:26.04:LTS
resteasy

Package

Name
resteasy
Purl
pkg:deb/ubuntu/resteasy?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.2-3
3.6.2-4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.2-4",
            "binary_name": "libresteasy-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
resteasy3.0

Package

Name
resteasy3.0
Purl
pkg:deb/ubuntu/resteasy3.0?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.26-6

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.26-6",
            "binary_name": "libresteasy3.0-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:Pro:16.04:LTS
resteasy

Package

Name
resteasy
Purl
pkg:deb/ubuntu/resteasy?arch=source&distro=esm-apps%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.6-3
3.0.6-3ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.6-3ubuntu0.1~esm1",
            "binary_name": "libresteasy-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:Pro:18.04:LTS
resteasy3.0

Package

Name
resteasy3.0
Purl
pkg:deb/ubuntu/resteasy3.0?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.19-1
3.0.19-2
3.0.26-1~18.04
3.0.26-1~18.04.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.26-1~18.04.1~esm1",
            "binary_name": "libresteasy3.0-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:Pro:20.04:LTS
resteasy

Package

Name
resteasy
Purl
pkg:deb/ubuntu/resteasy?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.2-2
3.6.2-2ubuntu0.20.04.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.2-2ubuntu0.20.04.1~esm1",
            "binary_name": "libresteasy-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
resteasy3.0

Package

Name
resteasy3.0
Purl
pkg:deb/ubuntu/resteasy3.0?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.26-1
3.0.26-1ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.0.26-1ubuntu0.1~esm1",
            "binary_name": "libresteasy3.0-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:Pro:22.04:LTS
resteasy

Package

Name
resteasy
Purl
pkg:deb/ubuntu/resteasy?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.2-2
3.6.2-2ubuntu0.22.04.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.2-2ubuntu0.22.04.1~esm1",
            "binary_name": "libresteasy-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"
Ubuntu:Pro:24.04:LTS
resteasy

Package

Name
resteasy
Purl
pkg:deb/ubuntu/resteasy?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.2-2
3.6.2-2ubuntu0.24.04.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.2-2ubuntu0.24.04.1~esm1",
            "binary_name": "libresteasy-java"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-17615.json"