← Vulnerability feed

Vulnerability record · CVE-2018-1051 · published 25 January 2018

CVE-2018-1051: Redhat resteasy improper input validation vulnerability

Redhat · Resteasy

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

8.1 CVSS 3.0 High EPSS 1.3% · top 30.7% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
8.1CVSS 3.0 base score, v2 6.8
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yaml.load()` in YamlProvider.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=1535411 Issue TrackingVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1535411 Issue TrackingVendor Advisory

Track CVE-2018-1051 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2016-9606Redhat resteasy improper input validation vulnerabilityJBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted dat…EPSS 5.9%7.5CVE-2020-14326Redhat integration camel k uncontrolled resource consumption vulnerabilityA vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with…EPSS 1.2%7.5CVE-2020-1695Redhat resteasy improper input validation vulnerabilityA flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v…EPSS 2.0%7.5CVE-2016-6346Redhat resteasy vulnerabilityRESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.EPSS 5.6%7.5CVE-2014-3490Redhat jboss enterprise application platform vulnerabilityRESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external…EPSS 4.6%6.5CVE-2016-6345Redhat resteasy information exposure vulnerabilityRESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.EPSS 1.8%6.4CVE-2014-7839Redhat resteasy improper input validation vulnerabilityDocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …EPSS 2.0%6.1CVE-2021-20293Redhat resteasy cross-site scripting vulnerabilityA reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2018-1051), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.