CVE-2024-1726
MEDIUMDescription
A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has knowledge of any POST, PUT, or PATCH request paths, they can potentially identify vulnerable endpoints and trigger excessive resource usage as the endpoints process the requests. This can result in a denial of service.
Is your site exposed to CVE-2024-1726?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-1726? +
How severe is CVE-2024-1726? +
How do I check if I'm vulnerable to CVE-2024-1726? +
Related Vulnerabilities
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …
SystemUI has an incorrect component protection setting, which allows access to specific information.
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages