cbcvebase.
CVE-2025-23184
published 2025-01-21

CVE-2025-23184: A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.94%
77.9th percentile
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).

Affected

6 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.5.103.5.10
apachecxf>= 3.6.0 < 3.6.53.6.5
apachecxf>= 4.0.0 < 4.0.64.0.6
apache_software_foundationapache_cxf< 3.5.103.5.10
apache_software_foundationapache_cxf>= 3.6.0 < 3.6.53.6.5
apache_software_foundationapache_cxf>= 4.0.0 < 4.0.64.0.6

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle7.5MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.