RHSA-2026:72424HighCVSS 7.5
Red Hat Security Advisory: resteasy security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-17615 — resteasy-core: RESTeasy SourceProvider remote unauthenticated file read
🎯 Affected products6
- Red Hat Enterprise Linux AppStream (v. 9)
- pki-resteasy-client-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- pki-resteasy-core-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- pki-resteasy-jackson2-provider-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- pki-resteasy-servlet-initializer-0:3.0.26-20.el9_8.noarch as a component of Red Hat Enterprise Linux AppStream (v. 9)
- resteasy-0:3.0.26-20.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, avoid exposing RESTEasy endpoints that return Source or StreamSource types. Alternatively, implement a custom MessageBodyWriter for Source types that explicitly applies XML security features to the SAXParserFactory before parsing. Changes to application configuration or code typically require an application redeployment or restart to take effect.