Executive brief
RESTEasy is a Jakarta RESTful Web Services implementation used to build APIs and web services. When its CorsFilter is misconfigured to allow all origins ("*"), it incorrectly reflects the caller's Origin header back to the client alongside credentials-enabled settings. An attacker can exploit this by hosting a malicious website that tricks authenticated users into making requests to the vulnerable API, allowing the attacker to steal sensitive data from the victim's authenticated session.
Technical details
The vulnerability is a CORS (Cross-Origin Resource Sharing) header injection flaw in RESTEasy's CorsFilter component. When the filter is configured with the permissive origin policy "*", it reflects the request's Origin header directly into the Access-Control-Allow-Origin response header while also setting Access-Control-Allow-Credentials: true. This violates CORS security semantics, which prohibit the wildcard origin from being used with credentialed requests. An attacker can leverage this by crafting a malicious cross-origin request from a website under their control; the browser will allow the credentialed request due to the permissive CORS headers, enabling the attacker to read authenticated API responses. The vulnerability requires the application to explicitly enable the wildcard origin policy and make credentialed requests (cookies or auth headers included), but no user interaction beyond visiting a malicious website is needed once the user is authenticated to the target service.
Affected products
- Red Hat RESTEasy <UNKNOWN>
Timeline
- 2026-09-18: disclosed