Medium severity5.3NVD Advisory· Published May 22, 2026· Updated Jul 23, 2026
CVE-2026-44618
CVE-2026-44618
Description
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.cxf:cxf-rt-ws-transferMaven | >= 4.2.0, < 4.2.1 | 4.2.1 |
org.apache.cxf:cxf-rt-ws-transferMaven | >= 4.1.0, < 4.1.6 | 4.1.6 |
org.apache.cxf:cxf-rt-ws-transferMaven | < 3.6.11 | 3.6.11 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vmm5-fjgx-2jhpghsaADVISORY
- lists.apache.org/thread/c7vb015f8ljmjl44030mn0yfq71f7sd7nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44618ghsaADVISORY
- www.openwall.com/lists/oss-security/2026/05/22/8nvdWEB
News mentions
0No linked articles in our index yet.