Inappropriate Encoding for Output Context Affecting pki-deps:10.6/resteasy package, versions *


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.57% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-PKIDEPS-18434026
  • published30 Jul 2026
  • disclosed10 Jul 2026

Introduced: 10 Jul 2026

NewCVE-2026-49844  (opens in a new tab)
CWE-838  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:8 pki-deps:10.6/resteasy.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pki-deps:10.6/resteasy package and not the pki-deps:10.6/resteasy package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.

The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.

The defect is reachable only when both of the following conditions hold:

An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.

Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.

CVSS Base Scores

version 3.1