Vulnerability GHSA-2hvc-5c6v-f533

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 months ago
May 26, 2026 at 01:30 PM UTC
Apache CXF: Untrusted JMS configuration can lead to RCE
4.2.0
4.2.0

Summary

Apache CXF: Untrusted JMS configuration can lead to RCE

Details

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Timeline

Published
4 months ago
May 26, 2026 at 01:30 PM UTC
Fixed (4.2.1)
Unknown
Unknown
Fixed (4.1.6)
Unknown
Unknown
Fixed (3.6.11)
Unknown
Unknown
Last Modified
3 months ago
June 29, 2026 at 11:26 PM UTC