← All Advisories

CVE-2026-17615

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-17615

Key Details

CVECVE-2026-17615
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productssee table below
Classified asCWE-611 (Improper Restriction of XML External Entity Reference)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack
Red HatRed Hat build of Apache Camel 4 for Quarkus 3
Red HatRed Hat build of Apicurio Registry 3
Red HatRed Hat build of Keycloak 26.6
Red HatRed Hat build of Debezium 3
Red HatRed Hat JBoss Enterprise Application Platform 8
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-17615
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-17615