CVE-2019-12406: Apache Cxf
Medium severity, CVSS 6.5. EPSS: 6.3% chance of exploitation in the next 30 days.
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".
Affected products
- Apache Cxf: before 3.2.11 (fixed in 3.2.11); from 3.3.0, before 3.3.4 (fixed in 3.3.4)
- Oracle Commerce Guided Search: version 11.3.2 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Retail Order Broker: version 15.0 only
Published 2019-11-06. Last modified 2026-06-17.