GHSA-hgjr-xwj3-jfvw
GitHub Security Advisory
JBoss RESTEasy vulnerable to Improper Input Validation
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.
Affected Packages
Maven
org.jboss.resteasy:resteasy-bom
Affected versions:
0
(fixed in 3.1.2.Final)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.