A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has knowledge of any POST, PUT, or PATCH request paths, they can potentially identify vulnerable endpoints and trigger excessive resource usage as the endpoints process the requests. This can result in a denial of service.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2024-04-25T16:29:04.615Z

Updated: 2024-06-05T09:04:22.004Z

Reserved: 2024-02-21T21:51:58.713Z


Link: CVE-2024-1726

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-04-25T17:15:48.257

Modified: 2024-04-25T17:24:59.967


Link: CVE-2024-1726

JSON object: View

cve-icon Redhat Information

No data.

CWE