VYPR
High severity7.5NVD Advisory· Published Jun 12, 2026· Updated Aug 7, 2026

CVE-2026-50645

CVE-2026-50645

Description

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.cxf:cxf-coreMaven
>= 4.2.0, < 4.2.24.2.2
org.apache.cxf:cxf-coreMaven
>= 4.0.0, < 4.1.74.1.7
org.apache.cxf:cxf-coreMaven
< 3.6.123.6.12

Affected products

15

Patches

Vulnerability mechanics

References

5

News mentions

1