{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredhatresteasy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89059"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RESTEasy"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","java","resteasy"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-89059 describes a critical vulnerability in the IIOImageProvider component of the Red Hat RESTEasy framework. The flaw stems from the application's failure to validate image dimensions and pixel counts declared within image request bodies. A remote, unauthenticated attacker can exploit this by crafting a small-sized image file that specifies extraordinarily large dimensions in its metadata. When the IIOImageProvider processes this request, it attempts to allocate memory proportional to the declared (rather than actual) size. This behavior forces the Java Virtual Machine (JVM) to perform excessive heap allocation, leading to memory exhaustion and a full application denial of service (DoS). This vulnerability is particularly dangerous in environments where RESTEasy handles public-facing image processing workflows. Defenders should prioritize auditing traffic patterns to image processing endpoints and implementing input validation constraints on image metadata.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial of service of the affected application. Because the attack requires only a single crafted request to trigger the memory exhaustion event, it poses a significant risk to the availability of systems relying on RESTEasy for image handling, particularly in high-traffic or resource-constrained environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests directed at endpoints utilizing the IIOImageProvider class.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all image-related request bodies to enforce limits on declared pixel dimensions and file metadata.\u003c/li\u003e\n\u003cli\u003eEvaluate the application heap memory configuration and monitor JVM memory usage patterns to detect anomalous spikes associated with image processing tasks.\u003c/li\u003e\n\u003cli\u003eReview Red Hat security advisories for the official patched version of RESTEasy and apply updates immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T12:04:53Z","date_published":"2026-09-18T12:04:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-resteasy-dos/","summary":"An unauthenticated remote attacker can trigger a denial of service in Red Hat RESTEasy by submitting a crafted image that causes excessive memory allocation within the JVM via the IIOImageProvider component.","title":"CVE-2026-89059: Denial of Service in RESTEasy IIOImageProvider","url":"https://feed.craftedsignal.io/briefs/2026-09-resteasy-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}