Denial of Service Vulnerability in RESTEasy IIOImageProvider Affects Red Hat
CVE-2026-89059
7.5HIGH
What is CVE-2026-89059?
A flaw in RESTEasy's IIOImageProvider permits remote, unauthenticated attackers to send specially crafted image requests, bypassing limits on declared dimensions and pixel counts. This can result in excessive memory allocation within the JVM, potentially leading to a denial of service as the JVM heap becomes exhausted.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Yu Bao (PayPal Cyber Security Team) for reporting this issue.