cbcvebase.

Apache Cxf vulnerabilities

57 known vulnerabilities affecting apache/cxf.

Total CVEs
57
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH17MEDIUM28

Vulnerabilities

Page 2 of 3
CVE-2019-12423P3HIGHCVSS 7.5fixed in 3.2.12≥ 3.3.0, < 3.3.5+1 more2020-01-16
CVE-2019-12423 [HIGH] CWE-522 CVE-2019-12423: Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry
nvd
CVE-2020-13954P3MEDIUMCVSS 6.1fixed in 3.3.8≥ 3.4.0, < 3.4.12020-11-12
CVE-2020-13954 [MEDIUM] CVE-2020-13954: By default, Apache CXF creates a /services page containing a listing of the available endpoint names By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and
nvd
CVE-2016-8739P3HIGHCVSS 7.5≤ 3.0.11v3.1.0+8 more2017-08-10
CVE-2016-8739 [HIGH] CWE-611 CVE-2016-8739: The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom J The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
nvd
CVE-2017-3156P3HIGHCVSS 7.5≤ 3.0.12v3.1.0+9 more2017-08-10
CVE-2017-3156 [HIGH] CVE-2017-3156: The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
nvd
CVE-2022-46363P3HIGHCVSS 7.5fixed in 3.4.10≥ 3.5.0, < 3.5.52022-12-13
CVE-2022-46363 [HIGH] CWE-20 CVE-2022-46363: A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remot A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerab
nvd
CVE-2017-5656P3HIGHCVSS 7.5≥ 3.0.0, < 3.0.13≥ 3.1.0, < 3.1.112017-04-18
CVE-2017-5656 [HIGH] CWE-384 CVE-2017-5656: Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associa Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
nvd
CVE-2012-2379P3CRITICALCVSS 10.0v2.4.0v2.4.1+11 more2013-01-03
CVE-2012-2379 [CRITICAL] CVE-2012-2379: Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token s Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
nvd
CVE-2025-23184P3HIGHCVSS 7.5fixed in 3.5.10≥ 3.6.0, < 3.6.5+1 more2025-01-21
CVE-2025-23184 [HIGH] CWE-400 CVE-2025-23184: A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6. A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
nvd
CVE-2024-32007P3HIGHCVSS 7.5fixed in 3.5.9≥ 3.6.0, < 3.6.4+1 more2024-07-19
CVE-2024-32007 [HIGH] CWE-20 CVE-2024-32007: An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 an An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
nvd
CVE-2012-5633P3MEDIUMCVSS 5.8≤ 2.5.7v2.5.0+13 more2013-03-12
CVE-2012-5633 [MEDIUM] CWE-287 CVE-2012-5633: The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, wh The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
nvd
CVE-2026-50630P3MEDIUMCVSS 6.5fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50630 [MEDIUM] CWE-113 CVE-2026-50630: A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response
nvd
CVE-2024-41172P3HIGHCVSS 7.5≥ 3.6.0, < 3.6.4≥ 4.0.0, < 4.0.52024-07-19
CVE-2024-41172 [HIGH] CWE-401 CVE-2024-41172: In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
nvd
CVE-2026-50645P3HIGHCVSS 7.5fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50645 [HIGH] CWE-400 CVE-2026-50645: There is no restriction on the amount of attachment headers that a message can contain when being de There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.
nvd
CVE-2017-5653P3MEDIUMCVSS 5.3≥ 3.0.0, ≤ 3.0.13≥ 3.1.0, ≤ 3.1.112017-04-18
CVE-2017-5653 [MEDIUM] CWE-295 CVE-2017-5653: JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that th JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
nvd
CVE-2012-5575P3MEDIUMCVSS 6.4v2.5.0v2.5.1+19 more2013-08-19
CVE-2012-5575 [MEDIUM] CWE-310 CVE-2012-5575: Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify t Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt commu
nvd
CVE-2013-0239P3MEDIUMCVSS 5.0≤ 2.5.8v2.4.0+24 more2013-03-12
CVE-2013-0239 [MEDIUM] CWE-287 CVE-2013-0239: Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToke Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
nvd
CVE-2026-50634P3MEDIUMCVSS 6.5fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50634 [MEDIUM] CWE-347 CVE-2026-50634: A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to proce A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity
nvd
CVE-2014-0034P3MEDIUMCVSS 4.3≤ 2.6.11v2.6.0+19 more2014-07-07
CVE-2014-0034 [MEDIUM] CWE-20 CVE-2014-0034: The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
nvd
CVE-2014-3623P4MEDIUMCVSS 5.0≥ 2.7.0, ≤ 2.7.13≥ 3.0.0, < 3.0.22014-10-30
CVE-2014-3623 [MEDIUM] CWE-287 CVE-2014-3623: Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
nvd
CVE-2016-6812P4MEDIUMCVSS 6.1≤ 3.0.11v3.1.0+8 more2017-08-10
CVE-2016-6812 [MEDIUM] CWE-79 CVE-2016-6812: The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServi The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWrit
nvd
Apache Cxf vulnerabilities | cvebase