{"id":"CVE-2026-89059","summary":"Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)","details":"A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.","aliases":["GHSA-m4pc-7gc7-9vw2"],"modified":"2026-09-20T14:16:35.193480Z","published":"2026-09-18T07:13:39.763Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-409"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89059.json","unresolved_ranges":[{"extracted_events":[{"fixed":"6.2.19.Final"},{"introduced":"7.0.0.Alpha1"},{"fixed":"7.0.5.Final"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-89059"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89059.json"},{"type":"ADVISORY","url":"https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89059"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519756"},{"type":"FIX","url":"https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb"},{"type":"PACKAGE","url":"https://github.com/resteasy/resteasy"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/resteasy/resteasy","events":[{"introduced":"0"},{"fixed":"7c7e6b37c8b2451a37aed9cdc6978b447456bacb"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v7.0.4.Final","v7.0.3.Final","v7.0.2.Final","v7.0.0.Final","v7.0.0.Beta5","v7.0.0.Beta4","v7.0.0.Beta3","v7.0.0.Beta2","v7.0.0.Beta1","7.0.0.Alpha4","7.0.0.Alpha3","7.0.0.Alpha2","7.0.0.Alpha1","6.2.2.Final","6.2.1.Final","6.2.0.Final","6.2.0.Beta1","6.1.0.Final","6.1.0.Beta3","6.1.0.Beta2","6.1.0.Beta1","6.1.0.Alpha1","6.0.0.Final","6.0.0.Beta1","5.0.0.Final","5.0.0.Beta3","5.0.0.Beta2","5.0.0.Beta1","5.0.0.Alpha1","4.7.0.Final","4.7.0.Beta1","4.4.2.Final","4.4.1.Final","4.4.0.Final","4.4.0.CR1","4.3.0.Final","4.2.0.Final","4.1.0.Final","4.0.0.CR2","4.0.0.CR1","4.0.0.Beta7","4.0.0.Beta6","4.0.0.Beta5","4.0.0.Beta4","4.0.0.Beta3","4.0.0.Beta2","4.0.0.Beta1","3.1.4.Final","3.1.3.Final","3.1.2.Final","3.1.1.Final","3.1.0.Beta1","3.1.0.Final","3.1.0.CR3","3.1.0.CR2","3.1.0.CR1","3.1.0.Beta2","3.0.16.Final","3.0.15.Final","3.0.14.Final","3.0.13.Final","3.0.10.Final","3.0.9.Final","3.0.8.Final","3.0.7.Final","3.0.6.Final","3.0.5.Final","3.0.4","3.0.2","3.0.1.Final","3.0.0.Final","3.0-rc-1","3.0-beta-6","3.0-beta-5","3.0-beta-4","3.0-beta-3","3.0-beta-2","3.0-beta-1"],"database_specific":{"vanir_signatures_modified":"2026-09-20T14:16:35Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb","target":{"file":"resteasy-core/src/main/java/org/jboss/resteasy/plugins/providers/IIOImageProviderHelper.java","function":"readImage"},"deprecated":false,"digest":{"function_hash":"72818372968371405491439509507717823279","length":202},"id":"CVE-2026-89059-410fbef9","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["97728258058544816004957738135948627883","277225259626050223963754197824424472281","104861131074000344537245127811394803876","105521377887849960965723874029594410558","98408534695236061767092211770526096831","219477713647064125439334731062287740678","330610207587412655921549031309798774408","333401632531303340302141094198439648043","8872333199681622956174137406762604675","56696934646108850776397078089572467826","119590764735634794177642404618353474056","167579054640525597957525344699869356036","203291498901860310198084804752524711764","20336738881372880353672519613634170936","158259341804675824510343583607171583934","43534959923489055825468574418775418576","205429568788342353740177262112033050375","238589175286512962030925275621620547394","256088021166405780217470682181013660508"],"threshold":0.9},"id":"CVE-2026-89059-4dd4b9c7","signature_type":"Line","signature_version":"v1","source":"https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb","target":{"file":"resteasy-core/src/main/java/org/jboss/resteasy/plugins/providers/IIOImageProviderHelper.java"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb","target":{"file":"resteasy-core-spi/src/main/java/org/jboss/resteasy/resteasy_jaxrs/i18n/Messages.java"},"deprecated":false,"digest":{"line_hashes":["43488508021642552777434816334393166452","130083499163662666249127700728448729065","223189749652368537677359447221427017532","184890472307517486039236504680324624312","271072172263586034189317986436488448459","54233657099444375447921120266740173582"],"threshold":0.9},"id":"CVE-2026-89059-8194da42"},{"digest":{"line_hashes":["246302272464557232268089755158194418901","139364369482902646250372899590878041623","116314609309993823143965014973361366937"],"threshold":0.9},"id":"CVE-2026-89059-9e2ae012","signature_type":"Line","signature_version":"v1","source":"https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb","target":{"file":"resteasy-core-spi/src/main/java/org/jboss/resteasy/spi/config/Options.java"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89059.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}