CVE-2024-29736: Apache Cxf

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.

Affected products

  • Apache Cxf: before 3.5.9 (fixed in 3.5.9); from 3.6.0, before 3.6.4 (fixed in 3.6.4); from 4.0.0, before 4.0.5 (fixed in 4.0.5)

Published 2024-07-19. Last modified 2026-06-17.