๐Ÿ” CVE Alert

CVE-2026-89058

HIGH 7.4

Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.

Vendor red hat
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for red hat

Be the first to know when new high vulnerabilities affecting red hat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Red Hat /
0 < 6.2.19.Final 7.0.0.Alpha1 < 7.0.5.Final

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-89058 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2519775 github.com: https://github.com/resteasy/resteasy/security/advisories/GHSA-972r-f3fv-whm3

Credits

Red Hat would like to thank Yu Bao (PayPal Cyber Security Team) for reporting this issue.