[ALSA-2026:72424] Important: resteasy security update
Type:
security
Severity:
important
Release date:
2026-09-28
Description:
RESTEasy contains a JBoss project that provides frameworks to help build RESTful Web Services and RESTful Java applications. It is a fully certified and portable implementation of the JAX-RS specification. Security Fix(es): * resteasy-core: RESTeasy SourceProvider remote unauthenticated file read (CVE-2026-17615) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch pki-resteasy-servlet-initializer-3.0.26-20.el9_8.noarch.rpm 1432be7017629df283a50f1d6ad47144babed061ba76bb347b0f65c08220e553
noarch pki-resteasy-core-3.0.26-20.el9_8.noarch.rpm 2aee3e8476f2051676c084f50306e164282500603c9d52a1ae72566f720d4fc7
noarch pki-resteasy-jackson2-provider-3.0.26-20.el9_8.noarch.rpm 5ac9a4d32d702ae283a2e63ba68ff54b27167fcf00cc5e7062cf921840e64eec
noarch pki-resteasy-client-3.0.26-20.el9_8.noarch.rpm a5355bcc3cafcce09a4fa18a5bf70dc2033dbb240ad76e1694ca4dc241a38ded
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.