cbcvebase.

Apache Cxf vulnerabilities

57 known vulnerabilities affecting apache/cxf.

Total CVEs
57
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH17MEDIUM28

Vulnerabilities

Page 1 of 3
CVE-2024-28752P2CRITICALCVSS 9.3PoCfixed in 3.5.8≥ 3.6.0, < 3.6.3+1 more2024-03-15
CVE-2024-28752 [CRITICAL] CWE-918 CVE-2024-28752: A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3 A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
nvd
CVE-2019-12419P2CRITICALCVSS 9.8≥ 3.2.0, < 3.2.11≥ 3.3.0, < 3.3.42019-11-06
CVE-2019-12419 [CRITICAL] CWE-863 CVE-2019-12419: Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to
nvd
CVE-2012-0803P2CRITICALCVSS 9.8v2.4.5v2.5.12017-08-08
CVE-2012-0803 [CRITICAL] CWE-287 CVE-2012-0803: The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authe The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request.
nvd
CVE-2013-2160P3MEDIUMCVSS 5.0PoCv2.5.0v2.5.1+19 more2013-08-19
CVE-2013-2160 [MEDIUM] CWE-399 CVE-2013-2160: The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7 The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.
nvd
CVE-2026-44930P2CRITICALCVSS 9.8fixed in 3.6.11≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44930 [CRITICAL] CWE-90 CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
nvd
CVE-2025-48913P3CRITICALCVSS 9.8fixed in 3.6.8≥ 4.0.0, < 4.0.9+1 more2025-08-08
CVE-2025-48913 [CRITICAL] CWE-20 CVE-2025-48913: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDA If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
nvd
CVE-2026-50628P3CRITICALCVSS 9.8fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50628 [CRITICAL] CWE-20 CVE-2026-50628: A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP addres A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2024-29736P3CRITICALCVSS 9.1fixed in 3.5.9≥ 3.6.0, < 3.6.4+1 more2024-07-19
CVE-2024-29736 [CRITICAL] CWE-918 CVE-2024-29736: A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3 A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
nvd
CVE-2010-2076P3CRITICALCVSS 9.8≥ 2.0.6, < 2.0.13≥ 2.1, < 2.1.10+1 more2010-08-19
CVE-2010-2076 [CRITICAL] CVE-2010-2076: Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache Servi Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi
nvd
CVE-2022-46364P3CRITICALCVSS 9.8fixed in 3.4.10≥ 3.5.0, < 3.5.52022-12-13
CVE-2022-46364 [CRITICAL] CWE-918 CVE-2022-46364: A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Ap A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
nvd
CVE-2026-49875P3CRITICALCVSS 9.8fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-49875 [CRITICAL] CWE-611 CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
nvd
CVE-2026-50632P3HIGHCVSS 8.1fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50632 [HIGH] CVE-2026-50632: A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lea A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2021-40690P3HIGHCVSS 7.5v3.4.42021-09-19
CVE-2021-40690 [HIGH] CWE-200 CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
nvd
CVE-2018-8039P3HIGHCVSS 8.1fixed in 3.1.16≥ 3.2.0, < 3.2.52018-07-02
CVE-2018-8039 [HIGH] CWE-755 CVE-2018-8039: It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProp It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the defaul
nvd
CVE-2026-50627P3CRITICALCVSS 9.1fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50627 [CRITICAL] CWE-289 CVE-2026-50627: The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4
nvd
CVE-2026-44417P3HIGHCVSS 7.5fixed in 3.6.11≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44417 [HIGH] CWE-20 CVE-2026-44417: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
nvd
CVE-2026-50633P3HIGHCVSS 8.1fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50633 [HIGH] CWE-20 CVE-2026-50633: A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2021-30468P3HIGHCVSS 7.5fixed in 3.3.11≥ 3.4.0, < 3.4.42021-06-16
CVE-2021-30468 [HIGH] CWE-400 CVE-2021-30468: A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malforme A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
nvd
CVE-2026-50631P3HIGHCVSS 7.4fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50631 [HIGH] CWE-367 CVE-2026-50631: A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Toke A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4
nvd
CVE-2021-22696P3HIGHCVSS 7.5fixed in 3.3.10≥ 3.4.0, < 3.4.32021-04-02
CVE-2021-22696 [HIGH] CWE-400 CVE-2021-22696: CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to que CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "reques
nvd
Apache Cxf vulnerabilities | cvebase