CVE-2024-32007: Apache Cxf
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
Affected products
- Apache Cxf: before 3.5.9 (fixed in 3.5.9); from 3.6.0, before 3.6.4 (fixed in 3.6.4); from 4.0.0, before 4.0.5 (fixed in 4.0.5)
Published 2024-07-19. Last modified 2026-06-17.