cbcvebase.
CVE-2026-57819
published 2026-08-06

CVE-2026-57819: Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
38.6th percentile
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.123.6.12
apachecxf>= 4.0.0 < 4.1.84.1.8
apachecxf>= 4.2.0 < 4.2.34.2.3
apache_software_foundationapache_cxf< 3.6.123.6.12
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.84.1.8
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.34.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.