High severity7.5NVD Advisory· Published Jun 12, 2026· Updated Aug 7, 2026
CVE-2026-50645
CVE-2026-50645
Description
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.cxf:cxf-coreMaven | >= 4.2.0, < 4.2.2 | 4.2.2 |
org.apache.cxf:cxf-coreMaven | >= 4.0.0, < 4.1.7 | 4.1.7 |
org.apache.cxf:cxf-coreMaven | < 3.6.12 | 3.6.12 |
Affected products
15- osv-coords13 versionspkg:apk/chainguard/apache-tika-2.9pkg:apk/chainguard/apache-tika-3.0pkg:apk/chainguard/apache-tika-3.1pkg:apk/chainguard/apache-tika-3.2pkg:apk/chainguard/apache-tika-3.3pkg:apk/chainguard/apache-tika-fips-2.9pkg:apk/chainguard/apache-tika-fips-3.0pkg:apk/chainguard/apache-tika-fips-3.1pkg:apk/chainguard/apache-tika-fips-3.2pkg:apk/chainguard/apache-tika-fips-3.3pkg:apk/wolfi/apache-tika-3.1pkg:apk/wolfi/apache-tika-3.2pkg:apk/wolfi/apache-tika-3.3
< 2.9.4-r20+ 12 more
- (no CPE)range: < 2.9.4-r20
- (no CPE)range: < 3.0.0-r31
- (no CPE)range: < 3.1.0-r38
- (no CPE)range: < 3.2.3-r18
- (no CPE)range: < 3.3.2-r2
- (no CPE)range: < 2.9.4-r12
- (no CPE)range: < 3.0.0-r13
- (no CPE)range: < 3.1.0-r15
- (no CPE)range: < 3.2.3-r13
- (no CPE)range: < 3.3.2-r4
- (no CPE)range: < 3.1.0-r38
- (no CPE)range: < 3.2.3-r18
- (no CPE)range: < 3.3.2-r2
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2026/06/11/12nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-ghvc-7hp8-2g2vghsaADVISORY
- lists.apache.org/thread/24zb7cqcvykhwm0j797dmdq25s61mj93nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-50645ghsaADVISORY
- cxf.apache.org/security-advisories.data/CVE-2026-50645.txtghsaWEB
News mentions
1- Apache CXF: Seven CVEs Disclosed Together, Including Two RCE Flaws and an Auth BypassVypr Intelligence · Jun 12, 2026