CVE-2026-50645: Apache Cxf
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per message.
Affected products
- Apache Cxf: before 4.1.7 (fixed in 4.1.7); from 4.2.0, before 4.2.2 (fixed in 4.2.2)
Published 2026-06-12. Last modified 2026-08-07.