Vulnerability GHSA-xw5h-cmh3-8j6j
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
3 months ago
June 12, 2026 at 12:31 PM UTC
Apache CXF has Improper Restriction of XML External Entity Reference
4.2.0 - 4.2.1
4.2.0 - 4.2.1
Summary
Apache CXF has Improper Restriction of XML External Entity Reference
Details
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 months ago
Apache cxf-core: No restriction on attachment headers per message
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
4.2.0 - 4.2.1 GHSA-ghvc-7hp8-2g2v
Medium Risk
1 year ago
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
4.1.0 GHSA-36wv-v2qp-v4g4
4.1.0 GHSA-36wv-v2qp-v4g4
High Risk
1 year ago
Apache CXF: Denial of Service vulnerability with temporary files
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.10, >=3.6.0 <3.6.5, >=4.0.0 <4.0.6 GHSA-fh5r-crhr-qrrq
Critical
3 years ago
Apache CXF Server-Side Request Forgery vulnerability
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-x3x3-qwjq-8gj4
High Risk
3 years ago
Apache CXF vulnerable to Exposure of Sensitive Information
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
>=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.10, >=3.5.0 <3.5.5 GHSA-3w37-5p3p-jv92
Impacted packages
Timeline
Published
3 months ago
June 12, 2026 at 12:31 PM UTC
Fixed (4.2.2)
Unknown
Unknown
Fixed (4.1.7)
Unknown
Unknown
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC