Severity: low 

Affected versions:

- Apache CXF (org.apache.cxf:cxf-core) 4.2.0 before 4.2.3
- Apache CXF (org.apache.cxf:cxf-core) 4.0.0 before 4.1.8
- Apache CXF (org.apache.cxf:cxf-core) before 3.6.12

Description:

Apache CXF allows to control the maximum attachment size via theĀ 
"attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there 
was no default placed on this size, meaning that a denial of service attack is 
possible if the user doesn't explicitly set the limit. Users should update to 
Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a 
default attachment size limit of 50mb.

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-54225

Reply via email to