VYPR
High severity7.5NVD Advisory· Published Aug 6, 2026· Updated Aug 6, 2026

CVE-2026-64958

CVE-2026-64958

Description

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected products

2
  • Apache/Cxfllm-fuzzy2 versions
    before 4.2.3, 4.1.8, or 3.6.12+ 1 more
    • (no CPE)range: before 4.2.3, 4.1.8, or 3.6.12
    • cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*range: <3.6.12

Patches

Vulnerability mechanics

References

1

News mentions

1