cbcvebase.
CVE-2025-48795
published 2025-07-15

CVE-2025-48795: Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is…

PriorityP430medium5.6CVSS 3.1
AVNACHPRNUINSUCLILAL
EPSS
0.62%
45.9th percentile
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF to encrypt temporary files to prevent sensitive credentials from being cached unencrypted on the local filesystem, however this bug means that the cached files are written out to logs unencrypted. Users are recommended to upgrade to versions 3.5.11, 3.6.6, 4.0.7 or 4.1.1, which fixes this issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachecxf
apachecxf
apachecxf
apachecxf
apache_software_foundationapache_cxf>= 3.5.10 < 3.5.113.5.11
apache_software_foundationapache_cxf>= 3.6.5 < 3.6.63.6.6
apache_software_foundationapache_cxf>= 4.0.6 < 4.0.74.0.7
apache_software_foundationapache_cxf>= 4.1.0 < 4.1.14.1.1

CVSS provenance

nvdv3.15.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_oracle5.9MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.