Vulnerability GHSA-2hvc-5c6v-f533
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 months ago
May 26, 2026 at 01:30 PM UTC
Apache CXF: Untrusted JMS configuration can lead to RCE
4.2.0
4.2.0
Summary
Apache CXF: Untrusted JMS configuration can lead to RCE
Details
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
3 months ago
Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory
4.2.0 - 4.2.1 GHSA-93g8-qqv3-mrx8
4.2.0 - 4.2.1 GHSA-93g8-qqv3-mrx8
Medium Risk
1 year ago
Apache CXF: Untrusted JMS configuration can lead to RCE
>=2.0.6 <2.0.14, >=2.1.0 <2.1.11, >=2.2.0 <2.2.13, >=2.3.0 <2.3.12, >=2.4.0 <2.4.11, >=2.5.0 <2.5.12, >=2.6.0 <2.6.18, >=2.7.0 <2.7.19, >=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.12, >=3.6.0 <3.6.8, >=4.0.0 <4.0.9, >=4.1.0 <4.1.3 GHSA-g4px-6qhm-hqjm
>=2.0.6 <2.0.14, >=2.1.0 <2.1.11, >=2.2.0 <2.2.13, >=2.3.0 <2.3.12, >=2.4.0 <2.4.11, >=2.5.0 <2.5.12, >=2.6.0 <2.6.18, >=2.7.0 <2.7.19, >=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.12, >=3.6.0 <3.6.8, >=4.0.0 <4.0.9, >=4.1.0 <4.1.3 GHSA-g4px-6qhm-hqjm
Impacted packages
Timeline
Published
4 months ago
May 26, 2026 at 01:30 PM UTC
Fixed (4.2.1)
Unknown
Unknown
Fixed (4.1.6)
Unknown
Unknown
Fixed (3.6.11)
Unknown
Unknown
Last Modified
3 months ago
June 29, 2026 at 11:26 PM UTC