Vulnerability GHSA-ghvc-7hp8-2g2v

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 12, 2026 at 12:31 PM UTC
Apache cxf-core: No restriction on attachment headers per message
4.2.0 - 4.2.1
4.2.0 - 4.2.1

Summary

Apache cxf-core: No restriction on attachment headers per message

Details

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per message.

Impacted packages

Timeline

Published
3 months ago
June 12, 2026 at 12:31 PM UTC
Fixed (4.2.2)
Unknown
Unknown
Fixed (4.1.7)
Unknown
Unknown
Fixed (3.6.12)
Unknown
Unknown
Last Modified
23 days ago
September 10, 2026 at 03:50 AM UTC