Vulnerability GHSA-ghvc-7hp8-2g2v
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 12, 2026 at 12:31 PM UTC
Apache cxf-core: No restriction on attachment headers per message
4.2.0 - 4.2.1
4.2.0 - 4.2.1
Summary
Apache cxf-core: No restriction on attachment headers per message
Details
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per message.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
3 months ago
Apache CXF has Improper Restriction of XML External Entity Reference
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
4.2.0 - 4.2.1 GHSA-xw5h-cmh3-8j6j
Medium Risk
1 year ago
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
4.1.0 GHSA-36wv-v2qp-v4g4
4.1.0 GHSA-36wv-v2qp-v4g4
High Risk
1 year ago
Apache CXF: Denial of Service vulnerability with temporary files
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
Critical
3 years ago
Apache CXF Server-Side Request Forgery vulnerability
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
High Risk
3 years ago
Apache CXF vulnerable to Exposure of Sensitive Information
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
Impacted packages
Timeline
Published
3 months ago
June 12, 2026 at 12:31 PM UTC
Fixed (4.2.2)
Unknown
Unknown
Fixed (4.1.7)
Unknown
Unknown
Fixed (3.6.12)
Unknown
Unknown
Last Modified
23 days ago
September 10, 2026 at 03:50 AM UTC