CVE-2026-54225

Apache CXF allows to control the maximum attachment size via theĀ "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-06 11:16

Updated : 2026-08-07 00:16


NVD link : CVE-2026-54225

Mitre link : CVE-2026-54225

CVE.ORG link : CVE-2026-54225


JSON object : View

Products Affected

apache

  • cxf
CWE
CWE-770

Allocation of Resources Without Limits or Throttling