{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-17615",
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "state": "PUBLISHED",
        "assignerShortName": "redhat",
        "dateReserved": "2026-07-27T19:28:37.735Z",
        "datePublished": "2026-08-31T16:15:01.739Z",
        "dateUpdated": "2026-08-31T17:09:20.602Z"
    },
    "containers": {
        "cna": {
            "title": "Resteasy-core: resteasy sourceprovider remote unauthenticated file read",
            "metrics": [
                {
                    "other": {
                        "content": {
                            "value": "Important",
                            "namespace": "https://access.redhat.com/security/updates/classification/"
                        },
                        "type": "Red Hat severity rating"
                    }
                },
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability."
                }
            ],
            "affected": [
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:camel_quarkus:3"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat build of Apicurio Registry 3",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:apicurio_registry:3"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat build of Debezium 3",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:debezium:3"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Build of Keycloak",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "keycloak/rhbk-rhel9-operator",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:build_keycloak:"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Build of Keycloak",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:build_keycloak:"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Build of Keycloak",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "rhbk/keycloak-rhel9-operator",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:build_keycloak:"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Build of Keycloak",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "rhbk-keycloak-rhel9-operator/rhbk-keycloak-rhel9-operator",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:build_keycloak:"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Build of Keycloak",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "rhbk-rhel9-operator/rhbk-rhel9-operator",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:build_keycloak:"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat build of Quarkus",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:quarkus:3"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Enterprise Linux 8",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "pki-core:10.6/resteasy",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/o:redhat:enterprise_linux:8"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Enterprise Linux 8",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "pki-deps:10.6/resteasy",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/o:redhat:enterprise_linux:8"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Enterprise Linux 9",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/o:redhat:enterprise_linux:9"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Fuse 7",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:jboss_fuse:7"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat JBoss Enterprise Application Platform 8",
                    "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                    "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
                    "packageName": "resteasy-core",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:jbosseapxp"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat Satellite 6",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "candlepin",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:satellite:6"
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://access.redhat.com/security/cve/CVE-2026-17615",
                    "tags": [
                        "vdb-entry",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2507635",
                    "name": "RHBZ#2507635",
                    "tags": [
                        "issue-tracking",
                        "x_refsource_REDHAT"
                    ]
                }
            ],
            "datePublic": "2026-08-31T00:00:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-611",
                            "description": "Improper Restriction of XML External Entity Reference",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "x_redhatCweChain": "CWE-611: Improper Restriction of XML External Entity Reference",
            "workarounds": [
                {
                    "lang": "en",
                    "value": "To mitigate this issue, avoid exposing RESTEasy endpoints that return Source or StreamSource types. Alternatively, implement a custom MessageBodyWriter for Source types that explicitly applies XML security features to the SAXParserFactory before parsing. Changes to application configuration or code typically require an application redeployment or restart to take effect."
                }
            ],
            "timeline": [
                {
                    "lang": "en",
                    "time": "2026-07-27T19:27:51.528Z",
                    "value": "Reported to Red Hat."
                },
                {
                    "lang": "en",
                    "time": "2026-08-31T00:00:00.000Z",
                    "value": "Made public."
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Red Hat would like to thank Leon Zlobecki for reporting this issue."
                }
            ],
            "providerMetadata": {
                "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
                "shortName": "redhat",
                "dateUpdated": "2026-08-31T16:54:18.242Z"
            },
            "x_generator": {
                "engine": "cvelib 1.8.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-31T17:09:02.820161Z",
                                "id": "CVE-2026-17615",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-31T17:09:20.602Z"
                }
            }
        ]
    }
}