Apache Software Foundation Apache Cxf vulnerabilities
32 known vulnerabilities affecting apache_software_foundation/apache_cxf.
Total CVEs
32
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM10
Vulnerabilities
Page 1 of 2
CVE-2024-28752P2CRITICALCVSS 9.3PoCfixed in 4.0.4, 3.6.3, 3.5.82024-03-15
CVE-2024-28752 [CRITICAL] CWE-918 CVE-2024-28752: A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
nvd
CVE-2026-44930P2CRITICALCVSS 9.8≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44930 [CRITICAL] CWE-90 CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
cvelistv5nvd
CVE-2025-48913P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.1.6+1 more2025-08-08
CVE-2025-48913 [CRITICAL] CWE-20 CVE-2025-48913: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDA
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
nvd
CVE-2026-50628P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50628 [CRITICAL] CWE-20 CVE-2026-50628: A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP addres
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2024-29736P3CRITICALCVSS 9.1fixed in 3.5.9, 3.6.4, 4.0.52024-07-19
CVE-2024-29736 [CRITICAL] CWE-918 CVE-2024-29736: A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
nvd
CVE-2022-46364P3CRITICALCVSS 9.8fixed in 3.5.5fixed in 3.4.102022-12-13
CVE-2022-46364 [CRITICAL] CWE-918 CVE-2022-46364: A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Ap
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
nvd
CVE-2026-49875P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-49875 [CRITICAL] CWE-611 CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
nvd
CVE-2018-8039P3HIGHCVSS 8.1vprior to 3.1.16v3.2.x prior to 3.2.52018-07-02
CVE-2018-8039 [HIGH] CWE-755 CVE-2018-8039: It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProp
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the defaul
nvd
CVE-2026-50627P3CRITICALCVSS 9.1≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50627 [CRITICAL] CWE-289 CVE-2026-50627: The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4
nvd
CVE-2026-44417P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.2fixed in 4.1.72026-05-22
CVE-2026-44417 [HIGH] CWE-20 CVE-2026-44417: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
cvelistv5nvd
CVE-2026-50633P3HIGHCVSS 8.1≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50633 [HIGH] CWE-20 CVE-2026-50633: A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2021-30468P3HIGHCVSS 7.5≥ Apache CXF, < 3.4.42021-06-16
CVE-2021-30468 [HIGH] CWE-400 CVE-2021-30468: A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malforme
A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
nvd
CVE-2026-50631P3HIGHCVSS 7.4≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50631 [HIGH] CWE-367 CVE-2026-50631: A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Toke
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4
nvd
CVE-2021-22696P3HIGHCVSS 7.5≥ unspecified, < 3.4.3≥ unspecified, < 3.3.102021-04-02
CVE-2021-22696 [HIGH] CWE-400 CVE-2021-22696: CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to que
CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR)). Instead of sending a JWT token as a "request" parameter, the spec also supports specifying a URI from which to retrieve a JWT token from via the "reques
nvd
CVE-2016-8739P3HIGHCVSS 7.5vprior to 3.0.12v3.1.x prior to 3.1.92017-08-10
CVE-2016-8739 [HIGH] CWE-611 CVE-2016-8739: The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom J
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
nvd
CVE-2017-3156P3HIGHCVSS 7.5vprior to 3.0.13v3.1.x prior to 3.1.102017-08-10
CVE-2017-3156 [HIGH] CVE-2017-3156: The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10
The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
nvd
CVE-2022-46363P3HIGHCVSS 7.5≥ 3.5, < 3.5.5≥ 3.4, < 3.4.102022-12-13
CVE-2022-46363 [HIGH] CWE-20 CVE-2022-46363: A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remot
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and redirect-query-check attributes. These attributes are not supposed to be used together, and so the vulnerab
nvd
CVE-2017-5656P3HIGHCVSS 7.5v3.1.x before 3.1.11vversions before 3.0.132017-04-18
CVE-2017-5656 [HIGH] CWE-384 CVE-2017-5656: Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associa
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
nvd
CVE-2025-23184P3HIGHCVSS 7.5fixed in 3.5.10≥ 3.6.0, < 3.6.5+1 more2025-01-21
CVE-2025-23184 [HIGH] CWE-400 CVE-2025-23184: A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
nvd
CVE-2024-32007P3HIGHCVSS 7.5fixed in 4.0.5, 3.6.4, 3.5.92024-07-19
CVE-2024-32007 [HIGH] CWE-20 CVE-2024-32007: An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 an
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
nvd
1 / 2Next →