CVE-2026-89059
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
वीकनेस
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
संदर्भ
- https://access.redhat.com/security/cve/CVE-2026-89059
- https://bugzilla.redhat.com/show_bug.cgi?id=2519756
- https://github.com/resteasy/resteasy/commit/7c7e6b37c8b2451a37aed9cdc6978b447456bacb
- https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
- https://bugzilla.redhat.com/show_bug.cgi?id=2519756
- https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।