RHSA-2026:72424HighCVSS 7.5

Red Hat Security Advisory: resteasy security update

Published
September 28, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-17615 — resteasy-core: RESTeasy SourceProvider remote unauthenticated file read

🎯 Affected products6

  • Red Hat Enterprise Linux AppStream (v. 9)
  • pki-resteasy-client-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-resteasy-core-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-resteasy-jackson2-provider-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • pki-resteasy-servlet-initializer-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • resteasy-0:3.0.26-20.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, avoid exposing RESTEasy endpoints that return Source or StreamSource types. Alternatively, implement a custom MessageBodyWriter for Source types that explicitly applies XML security features to the SAXParserFactory before parsing. Changes to application configuration or code typically require an application redeployment or restart to take effect.

🔗 References (4)