Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestion detail

Untriaged
Permalink CVE-2026-89058
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 3 days, 11 hours ago Activity log
  • Created suggestion
Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.

Affected products

RESTEasy
  • <7.0.5.Final
  • <6.2.19.Final
pki-core
candlepin
dogtag-pki
redhat-pki
resteasy-core
resteasy-jaxrs
pki-core:10.6/pki-core
jackson-jaxrs-providers
redhat-pki:10/redhat-pki
rhbk/keycloak-rhel9-operator
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8

Matching in nixpkgs

Package maintainers