🔐 CVE Alert

CVE-2026-54225

UNKNOWN 0.0

Apache CXF: Denial of Service attack via large attachments

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.

CWE CWE-770
Vendor apache software foundation
Product apache cxf
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache cxf

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache cxf are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache CXF
4.2.0 < 4.2.3 4.0.0 < 4.1.8 0 < 3.6.12

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/h2bjqm6g58z0j6893qzh728kdtk1byfy