Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.quarkus.resteasy.reactive/resteasy-reactive
  4. ›
  5. CVE-2024-1726

CVE-2024-1726: Quarkus: security checks in resteasy reactive may trigger a denial of service

April 25, 2024

A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has knowledge of any POST, PUT, or PATCH request paths, they can potentially identify vulnerable endpoints and trigger excessive resource usage as the endpoints process the requests. This can result in a denial of service.

References

  • access.redhat.com/errata/RHSA-2024:1662
  • access.redhat.com/security/cve/CVE-2024-1726
  • bugzilla.redhat.com/show_bug.cgi?id=2265158
  • github.com/advisories/GHSA-mv64-86g8-cqq7
  • github.com/quarkusio/quarkus
  • github.com/quarkusio/quarkus/commit/34c1a63baf5401d0d578a23a1a4deb4b841ce65b
  • github.com/quarkusio/quarkus/commit/96d93427f3b4a7d3cff34d8b7b883e13cecd359c
  • nvd.nist.gov/vuln/detail/CVE-2024-1726

Code Behaviors & Features

Detect and mitigate CVE-2024-1726 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.8.0.CR1 before 3.8.0, version 3.8.0.CR1, all versions starting from 3.3.0.CR1 before 3.7.4, all versions before 3.2.11.Final

Fixed versions

  • 3.8.0
  • 3.7.4
  • 3.2.11.Final

Solution

Upgrade to versions 3.2.11.Final, 3.7.4, 3.8.0 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-281: Improper Preservation of Permissions

Source file

maven/io.quarkus.resteasy.reactive/resteasy-reactive/CVE-2024-1726.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:52 +0000.