cbcvebase.

Apache Cxf vulnerabilities

57 known vulnerabilities affecting apache/cxf.

Total CVEs
57
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH17MEDIUM28

Vulnerabilities

Page 3 of 3
CVE-2019-12406P4MEDIUMCVSS 6.5fixed in 3.2.11≥ 3.3.0, < 3.3.42019-11-06
CVE-2019-12406 [MEDIUM] CWE-770 CVE-2019-12406: Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachm
nvd
CVE-2019-17573P3MEDIUMCVSS 6.1≥ 3.2.0, ≤ 3.2.12≥ 3.3.0, < 3.3.52020-01-16
CVE-2019-17573 [MEDIUM] CWE-79 CVE-2019-17573: By default, Apache CXF creates a /services page containing a listing of the available endpoint names By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in mod
nvd
CVE-2026-50629P3MEDIUMCVSS 5.3fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50629 [MEDIUM] CWE-93 CVE-2026-50629: The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2012-3451P4MEDIUMCVSS 4.3fixed in 2.4.9≥ 2.5.0, < 2.5.5+1 more2012-09-24
CVE-2012-3451 [MEDIUM] CWE-20 CVE-2012-3451: Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execu Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
nvd
CVE-2020-1954P4MEDIUMCVSS 5.3fixed in 3.2.13≥ 3.3.0, < 3.3.62020-04-01
CVE-2020-1954 [MEDIUM] CVE-2020-1954: Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind th
nvd
CVE-2026-50623P4MEDIUMCVSS 4.8fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50623 [MEDIUM] CWE-287 CVE-2026-50623: An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forg
nvd
CVE-2012-2378P4MEDIUMCVSS 4.3v2.4.5v2.4.6+5 more2013-01-05
CVE-2012-2378 [MEDIUM] CWE-264 CVE-2012-2378: Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enfor Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
nvd
CVE-2014-3584P4MEDIUMCVSS 5.0≤ 2.6.10v2.6.1+9 more2014-10-30
CVE-2014-3584 [MEDIUM] CWE-399 CVE-2014-3584: The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allo The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
nvd
CVE-2011-2487P4MEDIUMCVSS 5.9≥ 2.4.0, ≤ 2.4.6≥ 2.5.0, ≤ 2.5.22020-03-11
CVE-2011-2487 [MEDIUM] CWE-327 CVE-2011-2487: The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache W The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
nvd
CVE-2015-5253P4MEDIUMCVSS 4.0fixed in 2.7.18≥ 3.0.0, < 3.0.7+1 more2015-11-18
CVE-2015-5253 [MEDIUM] CWE-264 CVE-2015-5253: The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allo The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
nvd
CVE-2025-48795P4MEDIUMCVSS 5.6v3.5.10v3.6.5+2 more2025-07-15
CVE-2025-48795 [MEDIUM] CWE-400 CVE-2025-48795: Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF
nvd
CVE-2026-44618P4MEDIUMCVSS 5.3fixed in 3.6.11≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44618 [MEDIUM] CWE-611 CVE-2026-44618: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
nvd
CVE-2014-0035P4MEDIUMCVSS 4.3≤ 2.6.12v2.6.0+21 more2014-07-07
CVE-2014-0035 [MEDIUM] CWE-310 CVE-2014-0035: The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2017-12624P4MEDIUMCVSS 5.5≥ 3.0.0, < 3.0.16≥ 3.1.0, < 3.1.14+1 more2017-11-14
CVE-2017-12624 [MEDIUM] CVE-2017-12624: Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment header
nvd
CVE-2012-5786P4MEDIUMCVSS 5.8≤ 2.6.172012-11-04
CVE-2012-5786 [MEDIUM] CWE-20 CVE-2012-5786: The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary
nvd
CVE-2014-0110P4MEDIUMCVSS 4.3≤ 2.6.13v2.4.0+41 more2014-05-08
CVE-2014-0110 [MEDIUM] CWE-399 CVE-2014-0110: Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of servic Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.
nvd
CVE-2014-0109P4MEDIUMCVSS 4.3v2.7.0v2.7.1+41 more2014-05-08
CVE-2014-0109 [MEDIUM] CWE-399 CVE-2014-0109: Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of servic Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
nvd
Apache Cxf vulnerabilities | cvebase