cbcvebase.
CVE-2026-50645
published 2026-08-06

CVE-2026-50645: An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many…

PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.46%
38.3th percentile
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.123.6.12
apachecxf< 4.1.74.1.7
apachecxf>= 4.0.0 < 4.1.84.1.8
apachecxf>= 4.2.0 < 4.2.34.2.3
apachecxf>= 4.2.0 < 4.2.24.2.2
apache_software_foundationapache_cxf< 3.6.123.6.12
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.84.1.8
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.34.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.