Apache Cxf vulnerabilities
69 known vulnerabilities affecting apache/cxf.
Total CVEs
69
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH24MEDIUM28
Vulnerabilities
Page 3 of 4
CVE-2024-32007P3HIGHCVSS 7.5fixed in 3.5.9≥ 3.6.0, < 3.6.4+1 more2024-07-19
CVE-2024-32007 [HIGH] CWE-20 CVE-2024-32007: An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 an
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
nvd
CVE-2012-5633P3MEDIUMCVSS 5.8≤ 2.5.7v2.5.0+13 more2013-03-12
CVE-2012-5633 [MEDIUM] CWE-287 CVE-2012-5633: The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, wh
The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.
nvd
CVE-2026-64958P3HIGHCVSS 7.5fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-64958 [HIGH] CVE-2026-64958: An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
nvd
CVE-2024-41172P3HIGHCVSS 7.5≥ 3.6.0, < 3.6.4≥ 4.0.0, < 4.0.52024-07-19
CVE-2024-41172 [HIGH] CWE-401 CVE-2024-41172: In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
nvd
CVE-2026-50645P3HIGHCVSS 7.5fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50645 [HIGH] CWE-400 CVE-2026-50645: There is no restriction on the amount of attachment headers that a message can contain when being de
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per
nvd
CVE-2017-5653P3MEDIUMCVSS 5.3≥ 3.0.0, ≤ 3.0.13≥ 3.1.0, ≤ 3.1.112017-04-18
CVE-2017-5653 [MEDIUM] CWE-295 CVE-2017-5653: JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that th
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
nvd
CVE-2012-5575P3MEDIUMCVSS 6.4v2.5.0v2.5.1+19 more2013-08-19
CVE-2012-5575 [MEDIUM] CWE-310 CVE-2012-5575: Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify t
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt commu
nvd
CVE-2026-50634P3MEDIUMCVSS 6.5fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50634 [MEDIUM] CWE-347 CVE-2026-50634: A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to proce
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption
that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity
nvd
CVE-2013-0239P3MEDIUMCVSS 5.0≤ 2.5.8v2.4.0+24 more2013-03-12
CVE-2013-0239 [MEDIUM] CWE-287 CVE-2013-0239: Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToke
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security header of a SOAP request containing a UsernameToken element that lacks a password child element.
nvd
CVE-2014-0034P3MEDIUMCVSS 4.3≤ 2.6.11v2.6.0+19 more2014-07-07
CVE-2014-0034 [MEDIUM] CWE-20 CVE-2014-0034: The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.
nvd
CVE-2014-3623P4MEDIUMCVSS 5.0≥ 2.7.0, ≤ 2.7.13≥ 3.0.0, < 3.0.22014-10-30
CVE-2014-3623 [MEDIUM] CWE-287 CVE-2014-3623: Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
nvd
CVE-2016-6812P4MEDIUMCVSS 6.1≤ 3.0.11v3.1.0+8 more2017-08-10
CVE-2016-6812 [MEDIUM] CWE-79 CVE-2016-6812: The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServi
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWrit
nvd
CVE-2019-12406P4MEDIUMCVSS 6.5fixed in 3.2.11≥ 3.3.0, < 3.3.42019-11-06
CVE-2019-12406 [MEDIUM] CWE-770 CVE-2019-12406: Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachm
nvd
CVE-2019-17573P3MEDIUMCVSS 6.1≥ 3.2.0, ≤ 3.2.12≥ 3.3.0, < 3.3.52020-01-16
CVE-2019-17573 [MEDIUM] CWE-79 CVE-2019-17573: By default, Apache CXF creates a /services page containing a listing of the available endpoint names
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in mod
nvd
CVE-2026-50629P3MEDIUMCVSS 5.3fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50629 [MEDIUM] CWE-93 CVE-2026-50629: The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes th
nvd
CVE-2012-3451P4MEDIUMCVSS 4.3fixed in 2.4.9≥ 2.5.0, < 2.5.5+1 more2012-09-24
CVE-2012-3451 [MEDIUM] CWE-20 CVE-2012-3451: Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execu
Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
nvd
CVE-2020-1954P4MEDIUMCVSS 5.3fixed in 3.2.13≥ 3.3.0, < 3.3.62020-04-01
CVE-2020-1954 [MEDIUM] CVE-2020-1954: Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind th
nvd
CVE-2012-2378P4MEDIUMCVSS 4.3v2.4.5v2.4.6+5 more2013-01-05
CVE-2012-2378 [MEDIUM] CWE-264 CVE-2012-2378: Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enfor
Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
nvd
CVE-2014-3584P4MEDIUMCVSS 5.0≤ 2.6.10v2.6.1+9 more2014-10-30
CVE-2014-3584 [MEDIUM] CWE-399 CVE-2014-3584: The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allo
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
nvd
CVE-2026-50623P4MEDIUMCVSS 4.8fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50623 [MEDIUM] CWE-287 CVE-2026-50623: An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forg
nvd