๐Ÿ” CVE Alert

CVE-2026-107937

UNKNOWN 0.0

Apache CXF: The attachment header size and count limits can be bypassed, which allows denial of service through memory exhaustion.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service.ย  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Vendor apache software foundation
Product apache cxf
Published Oct 9, 2026
Last Updated Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache cxf

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache cxf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache CXF
4.2.0 < 4.2.4 4.0.0 < 4.1.9 0 < 3.6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread.html/x9twtpv3d04qj83t6w9xkh9y2q28zztj openwall.com: http://www.openwall.com/lists/oss-security/2026/10/09/12

Credits

This issue was found using Claude agents to study the security of open-source projects and independently by Mike Read (github.com/Michael-JRead)