CVE-2026-44618
published 2026-05-22CVE-2026-44618: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.30%
22.5th percentile
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.6.11 | 3.6.11 |
| apache | cxf | — | — |
| apache | cxf | >= 4.0.0 < 4.1.6 | 4.1.6 |
| apache_software_foundation | apache_cxf | < 3.6.11 | 3.6.11 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.6 | 4.1.6 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.1 | 4.2.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvelistv5v3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vmm5-fjgx-2jhp: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks
ghsa_unreviewed·2026-05-26
CVE-2026-44618 [MEDIUM] CWE-611 GHSA-vmm5-fjgx-2jhp: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
GHSA
Apache CXF's WS-Transfer module has an insecure XML parser configuration
ghsa·2026-05-26
CVE-2026-44618 [MEDIUM] CWE-611 Apache CXF's WS-Transfer module has an insecure XML parser configuration
Apache CXF's WS-Transfer module has an insecure XML parser configuration
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
VulDB
Apache CXF up to 3.6.10/4.1.5/4.2.0 WS-Transfer xml external entity reference (WID-SEC-2026-1659)
vuldb·2026-05-22
CVE-2026-44618 [CRITICAL] Apache CXF up to 3.6.10/4.1.5/4.2.0 WS-Transfer xml external entity reference (WID-SEC-2026-1659)
A vulnerability marked as problematic has been reported in Apache CXF up to 3.6.10/4.1.5/4.2.0. This impacts an unknown function of the component WS-Transfer Module. Performing a manipulation results in xml external entity reference.
This vulnerability is reported as CVE-2026-44618. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
CVEList
Apache CXF: XXE vulnerability in WS-Transfer functionality
cvelistv5·2026-05-22·CVSS 5.3
CVE-2026-44618 [MEDIUM] CWE-611 Apache CXF: XXE vulnerability in WS-Transfer functionality
Apache CXF: XXE vulnerability in WS-Transfer functionality
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Red Hat
org.apache.cxf/cxf-rt-ws-transfer: Apache CXF: XML External Entity (XXE) attack via insecure XML parser configuration
vendor_redhat·2026-05-22·CVSS 5.3
CVE-2026-44618 [MEDIUM] CWE-112 org.apache.cxf/cxf-rt-ws-transfer: Apache CXF: XML External Entity (XXE) attack via insecure XML parser configuration
org.apache.cxf/cxf-rt-ws-transfer: Apache CXF: XML External Entity (XXE) attack via insecure XML parser configuration
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
A flaw was found in Apache CXF. An insecure XML parser configuration within Apache CXF's WS-Transfer module may allow a remote attacker to perform XML External Entity (XXE) attacks. This could lead to information disclosure, denial of service, or server-side request forgery.
Package: cxf-rt-ws-transfer (Red Hat build of Apache Camel for Spring Boot 4) - Not affected
Package: cxf-rt-ws-transfer (Red Hat Fuse 7) - Not affected
Package: cxf-rt-ws-transfer (Red Hat JBoss E
No detection rules found.
No public exploits indexed.
2026-05-22
Published