High severity7.5NVD Advisory· Published Jun 12, 2026· Updated Jun 13, 2026
CVE-2026-50645
CVE-2026-50645
Description
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/11/12nvdMailing ListThird Party Advisory
- lists.apache.org/thread/24zb7cqcvykhwm0j797dmdq25s61mj93nvdVendor Advisory
News mentions
1- Apache CXF: Seven CVEs Disclosed Together, Including Two RCE Flaws and an Auth BypassVypr Intelligence · Jun 12, 2026