Apache CXF allows to control the maximum attachment size via theĀ "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/h2bjqm6g58z0j6893qzh728kdtk1byfy | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/08/06/14 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-06 11:16
Updated : 2026-08-07 00:16
NVD link : CVE-2026-54225
Mitre link : CVE-2026-54225
CVE.ORG link : CVE-2026-54225
JSON object : View
Products Affected
apache
- cxf
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
