Apache Software Foundation Apache Cxf vulnerabilities
32 known vulnerabilities affecting apache_software_foundation/apache_cxf.
Total CVEs
32
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM10
Vulnerabilities
Page 2 of 2
CVE-2026-50630P3MEDIUMCVSS 6.5≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50630 [MEDIUM] CWE-113 CVE-2026-50630: A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response
nvd
CVE-2024-41172P3HIGHCVSS 7.5≥ 3.6.0, 4.0.0, < 3.6.4, 4.0.52024-07-19
CVE-2024-41172 [HIGH] CWE-401 CVE-2024-41172: In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
nvd
CVE-2026-50645P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50645 [HIGH] CWE-400 CVE-2026-50645: There is no restriction on the amount of attachment headers that a message can contain when being de
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.
nvd
CVE-2017-5653P3MEDIUMCVSS 5.3vprior to 3.0.13v3.1.x prior to 3.1.112017-04-18
CVE-2017-5653 [MEDIUM] CWE-295 CVE-2017-5653: JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that th
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
nvd
CVE-2026-50634P3MEDIUMCVSS 6.5≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50634 [MEDIUM] CWE-347 CVE-2026-50634: A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to proce
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption
that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity
nvd
CVE-2016-6812P4MEDIUMCVSS 6.1vprior to 3.0.12v3.1.x prior to 3.1.92017-08-10
CVE-2016-6812 [MEDIUM] CWE-79 CVE-2016-6812: The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServi
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWrit
nvd
CVE-2019-17573P3MEDIUMCVSS 6.1≥ unspecified, < 3.4.1≥ unspecified, < 3.3.82020-01-16
CVE-2019-17573 [MEDIUM] CWE-79 CVE-2019-17573: By default, Apache CXF creates a /services page containing a listing of the available endpoint names
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in mod
nvd
CVE-2026-50629P3MEDIUMCVSS 5.3≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50629 [MEDIUM] CWE-93 CVE-2026-50629: The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
nvd
CVE-2026-50623P4MEDIUMCVSS 4.8≥ 4.2.0, < 4.2.2fixed in 4.1.72026-06-12
CVE-2026-50623 [MEDIUM] CWE-287 CVE-2026-50623: An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forg
nvd
CVE-2025-48795P4MEDIUMCVSS 5.6≥ 3.5.10, < 3.5.11≥ 3.6.5, < 3.6.6+2 more2025-07-15
CVE-2025-48795 [MEDIUM] CWE-400 CVE-2025-48795: Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial of service attack by causing an out of memory exception. In addition, it is possible to configure CXF
nvd
CVE-2026-44618P4MEDIUMCVSS 5.3≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44618 [MEDIUM] CWE-611 CVE-2026-44618: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
cvelistv5nvd
CVE-2017-12624P4MEDIUMCVSS 5.5vprior to 3.1.14v3.2.x prior to 3.2.12017-11-14
CVE-2017-12624 [MEDIUM] CVE-2017-12624: Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment header
nvd
← Previous2 / 2