Vulnerability GHSA-fh5r-crhr-qrrq
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 year ago
January 21, 2025 at 12:30 PM UTC
Apache CXF: Denial of Service vulnerability with temporary files
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6
Summary
Apache CXF: Denial of Service vulnerability with temporary files
Details
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 months ago
Apache cxf-core: No restriction on attachment headers per message
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
Critical
3 months ago
Apache CXF has Improper Restriction of XML External Entity Reference
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
Medium Risk
1 year ago
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
4.1.0 GHSA-36wv-v2qp-v4g4
4.1.0 GHSA-36wv-v2qp-v4g4
Critical
3 years ago
Apache CXF Server-Side Request Forgery vulnerability
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
High Risk
3 years ago
Apache CXF vulnerable to Exposure of Sensitive Information
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
Impacted packages
Timeline
Published
1 year ago
January 21, 2025 at 12:30 PM UTC
Fixed (3.5.10)
Unknown
Unknown
Fixed (3.6.5)
Unknown
Unknown
Fixed (4.0.6)
Unknown
Unknown
Last Modified
23 days ago
September 10, 2026 at 03:50 AM UTC