cbcvebase.

Apache Cxf vulnerabilities

69 known vulnerabilities affecting apache/cxf.

Total CVEs
69
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH24MEDIUM28

Vulnerabilities

Page 4 of 4
CVE-2011-2487P4MEDIUMCVSS 5.9≥ 2.4.0, ≤ 2.4.6≥ 2.5.0, ≤ 2.5.22020-03-11
CVE-2011-2487 [MEDIUM] CWE-327 CVE-2011-2487: The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache W The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is susceptible to a Bleichenbacher attack.
nvd
CVE-2015-5253P4MEDIUMCVSS 4.0fixed in 2.7.18≥ 3.0.0, < 3.0.7+1 more2015-11-18
CVE-2015-5253 [MEDIUM] CWE-264 CVE-2015-5253: The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allo The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
nvd
CVE-2025-48795P4MEDIUMCVSS 5.6v3.5.10v3.6.5+2 more2025-07-15
CVE-2025-48795 [MEDIUM] CWE-400 CVE-2025-48795: Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF
nvd
CVE-2026-44618P4MEDIUMCVSS 5.3fixed in 3.6.11≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44618 [MEDIUM] CWE-611 CVE-2026-44618: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
nvd
CVE-2014-0035P4MEDIUMCVSS 4.3≤ 2.6.12v2.6.0+21 more2014-07-07
CVE-2014-0035 [MEDIUM] CWE-310 CVE-2014-0035: The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2017-12624P4MEDIUMCVSS 5.5≥ 3.0.0, < 3.0.16≥ 3.1.0, < 3.1.14+1 more2017-11-14
CVE-2017-12624 [MEDIUM] CVE-2017-12624: Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment header
nvd
CVE-2012-5786P4MEDIUMCVSS 5.8≤ 2.6.172012-11-04
CVE-2012-5786 [MEDIUM] CWE-20 CVE-2012-5786: The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary
nvd
CVE-2014-0110P4MEDIUMCVSS 4.3≤ 2.6.13v2.4.0+41 more2014-05-08
CVE-2014-0110 [MEDIUM] CWE-399 CVE-2014-0110: Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of servic Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.
nvd
CVE-2014-0109P4MEDIUMCVSS 4.3v2.7.0v2.7.1+41 more2014-05-08
CVE-2014-0109 [MEDIUM] CWE-399 CVE-2014-0109: Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of servic Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
nvd
Apache Cxf vulnerabilities | cvebase