Bug 2507635 (CVE-2026-17615)
| Summary: | CVE-2026-17615 resteasy-core: RESTeasy SourceProvider remote unauthenticated file read | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anthomas, ant, anujha, aschwart, asoldano, aszczucz, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, dandread, dkreling, dlofthou, drichtar, ehelms, ewittman, fmongiar, ggainey, gmalinko, gsmet, istudens, ivassile, iweiss, janstey, jmartisk, jnethert, jpasqual, jpechane, juwatts, kaycoth, lthon, manderse, mdellweg, mhulan, mosmerov, mposolda, msvehla, nipatil, nmoumoul, nwallace, olubyans, osousa, pantinor, pberan, pcreech, pdelbell, pesilva, pgallagh, pjindal, pmackay, probinso, rchan, rguimara, rhel-process-autobot, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sbiarozk, security-response-team, smallamp, ssilvert, sthorger, thjenkin, tmalecek, tqvarnst, vdosoudi, vmuzikar, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2531001 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-27 19:38:02 UTC
This issue has been addressed in the following products: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP1 Via RHSA-2026:63302 https://access.redhat.com/errata/RHSA-2026:63302 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:72424 https://access.redhat.com/errata/RHSA-2026:72424 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:77297 https://access.redhat.com/errata/RHSA-2026:77297 |