Impact
RESTEasy’s IIOImageProvider decodes image request bodies without imposing limits on the declared image dimensions or pixel count. An attacker can send a small payload that declares enormous dimensions, causing the runtime to allocate a very large block of memory, exhausting the Java Virtual Machine heap and disrupting service availability.
Affected Systems
The vulnerability affects a wide range of Red Hat products that incorporate RESTEasy, including Red Hat Build of Keycloak, Red Hat Certificate System 10 and 11, Red Hat Enterprise Linux 8, 9 and 10, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Satellite 6, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Apicurio Registry 3, Debezium 3 and Quarkus 3. Specific version information is not detailed in the advisory, but all deployed instances that use the affected RESTEasy component are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1 % reflects a low but non‑zero probability of real‑world exploitation. The vulnerability is not listed in CISA’s KEV catalog. A remote, unauthenticated attacker can trigger the issue by sending a crafted image via an HTTP request; the lack of authentication requirements means that any external user can attempt the attack. Successful exploitation leads to denial of service through memory exhaustion, potentially affecting entire application deployments that rely on the vulnerable RESTEasy component.
OpenCVE Enrichment