CVE-2026-50627
- EPSS 0.45%
- Veröffentlicht 12.06.2026 08:55:41
- Zuletzt bearbeitet 07.08.2026 13:16:50
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, ...
CVE-2026-49875
- EPSS 0.53%
- Veröffentlicht 12.06.2026 08:54:50
- Zuletzt bearbeitet 07.08.2026 13:16:49
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versio...
CVE-2026-50623
- EPSS 0.37%
- Veröffentlicht 12.06.2026 08:52:05
- Zuletzt bearbeitet 07.08.2026 13:16:50
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unaut...
CVE-2026-44417
- EPSS 0.64%
- Veröffentlicht 22.05.2026 12:17:25
- Zuletzt bearbeitet 23.07.2026 16:10:00
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Us...
CVE-2026-44618
- EPSS 0.3%
- Veröffentlicht 22.05.2026 12:17:14
- Zuletzt bearbeitet 23.07.2026 16:10:00
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
CVE-2026-44930
- EPSS 0.69%
- Veröffentlicht 22.05.2026 12:16:47
- Zuletzt bearbeitet 23.07.2026 16:10:00
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, wh...
CVE-2025-48913
- EPSS 0.79%
- Veröffentlicht 08.08.2025 09:21:22
- Zuletzt bearbeitet 04.11.2025 22:16:17
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. U...
CVE-2025-48795
- EPSS 0.62%
- Veröffentlicht 15.07.2025 14:26:44
- Zuletzt bearbeitet 04.11.2025 22:16:17
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cause a denial...
CVE-2025-23184
- EPSS 2.13%
- Veröffentlicht 21.01.2025 10:15:08
- Zuletzt bearbeitet 15.12.2025 16:15:52
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it...
CVE-2024-41172
- EPSS 1.2%
- Veröffentlicht 19.07.2024 09:15:05
- Zuletzt bearbeitet 21.11.2024 09:32:20
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase...