VYPR

StaxUtils

by Apache

CVEs (1)

  • CVE-2026-108039Oct 9, 2026
    risk 0.00cvss —epss —

    By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or…