CVE-2025-48795
published 2025-07-15CVE-2025-48795: Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is…
PriorityP430medium5.6CVSS 3.1
AVNACHPRNUINSUCLILAL
EPSS
0.62%
45.9th percentile
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted.
Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache_software_foundation | apache_cxf | >= 3.5.10 < 3.5.11 | 3.5.11 |
| apache_software_foundation | apache_cxf | >= 3.6.5 < 3.6.6 | 3.6.6 |
| apache_software_foundation | apache_cxf | >= 4.0.6 < 4.0.7 | 4.0.7 |
| apache_software_foundation | apache_cxf | >= 4.1.0 < 4.1.1 | 4.1.1 |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_oracle5.9MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
ghsa·2025-07-15
CVE-2025-48795 [MEDIUM] CWE-400 Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted.
Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.
OSV
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
osv·2025-07-15
CVE-2025-48795 [MEDIUM] Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted.
Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Integrators (Apache CXF) — CVE-2025-48795
vendor_oracle·2026-01-15·CVSS 5.6
CVE-2025-48795 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Integrators (Apache CXF) — CVE-2025-48795
Oracle Oracle Construction and Engineering Risk Matrix: Integrators (Apache CXF) vulnerability
CVE: CVE-2025-48795
CVSS: 5.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache CXF) — CVE-2025-48795
vendor_oracle·2025-10-15·CVSS 4.1
CVE-2025-48795 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache CXF) — CVE-2025-48795
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Apache CXF) vulnerability
CVE: CVE-2025-48795
CVSS: 4.1
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
org.apache.cxf/cxf: Apache CXF denial of service and data exposure
vendor_redhat·2025-07-15·CVSS 5.6
CVE-2025-48795 [MEDIUM] CWE-770 org.apache.cxf/cxf: Apache CXF denial of service and data exposure
org.apache.cxf/cxf: Apache CXF denial of service and data exposure
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted.
Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.
A log processing flaw was found in Apache CXF. Large stream-based messages are st
Oracle
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Mina SSHD) — CVE-2023-48795
vendor_oracle·2025-04-15·CVSS 5.9
CVE-2023-48795 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Mina SSHD) — CVE-2023-48795
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Mina SSHD) vulnerability
CVE: CVE-2023-48795
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Database Server Risk Matrix: Database Migration Assistant for Unicode (Apache Mina SSHD) — CVE-2023-48795
vendor_oracle·2025-01-15·CVSS 5.9
CVE-2023-48795 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Database Migration Assistant for Unicode (Apache Mina SSHD) — CVE-2023-48795
Oracle Oracle Database Server Risk Matrix: Database Migration Assistant for Unicode (Apache Mina SSHD) vulnerability
CVE: CVE-2023-48795
CVSS: 5.9
Protocol: SSH
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
No detection rules found.
No public exploits indexed.
2025-07-15
Published