CVE-2026-64958: Apache Cxf

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected products

  • Apache Cxf: before 3.6.12 (fixed in 3.6.12); from 4.0.0, before 4.1.8 (fixed in 4.1.8); from 4.2.0, before 4.2.3 (fixed in 4.2.3)

Published 2026-08-06. Last modified 2026-08-06.