CVE-2025-48913
- EPSS 0.11%
- Published 08.08.2025 09:21:22
- Last modified 14.08.2025 19:46:03
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. U...
CVE-2025-48795
- EPSS 0.08%
- Published 15.07.2025 14:26:44
- Last modified 29.07.2025 16:57:13
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial...
CVE-2025-23184
- EPSS 0.29%
- Published 21.01.2025 10:15:08
- Last modified 15.02.2025 01:15:11
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it...
CVE-2024-41172
- EPSS 0.45%
- Published 19.07.2024 09:15:05
- Last modified 21.11.2024 09:32:20
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase...
CVE-2024-32007
- EPSS 0.17%
- Published 19.07.2024 09:15:04
- Last modified 21.11.2024 09:14:20
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.
CVE-2024-29736
- EPSS 0.2%
- Published 19.07.2024 09:15:04
- Last modified 21.11.2024 09:08:12
A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
CVE-2024-28752
- EPSS 0.36%
- Published 15.03.2024 11:15:09
- Last modified 27.06.2025 15:06:40
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (inclu...
CVE-2022-46364
- EPSS 0.1%
- Published 13.12.2022 17:15:17
- Last modified 22.04.2025 03:15:20
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
CVE-2022-46363
- EPSS 0.07%
- Published 13.12.2022 15:15:11
- Last modified 22.04.2025 03:15:20
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources-list and red...
CVE-2021-40690
- EPSS 0.44%
- Published 19.09.2021 18:15:07
- Last modified 21.11.2024 06:24:34
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacke...