org.apache.cxf:cxf-core
Maven14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.cxf:cxf-corepage 1 of 1
- CVE-2014-0035MEDIUMCVSS v2 4.3EG 4.3fixed in 2.6.13 or 2.7.10, by version range2014-07-07
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remot…
- CVE-2014-0109MEDIUMCVSS v2 4.3EG 4.3fixed in 2.6.14 or 2.7.11, by version range2014-05-08
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
- CVE-2014-0110MEDIUMCVSS v2 4.3EG 4.3fixed in 2.6.14 or 2.7.11, by version range2014-05-08
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.
- CVE-2016-6812MEDIUMCVSS 6.1EG 6.1fixed in 3.0.12 or 3.1.9, by version range2017-08-10
vulnerable: 3.1.0 ... 3.1.8 (9 versions)
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calcul…
- CVE-2016-8739HIGHCVSS 7.5EG 7.5fixed in 3.0.12 or 3.1.9, by version range2017-08-10
vulnerable: 3.1.0 ... 3.1.8 (9 versions)
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
- CVE-2017-12624MEDIUMCVSS 5.5EG 5.5fixed in 3.2.1, 3.1.14 or 3.0.16, by version range2017-11-14
vulnerable: 3.0.0 ... 3.0.9 (18 versions)
Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Bo…
- CVE-2017-5653MEDIUMCVSS 5.3EG 5.3fixed in 3.1.11 or 3.0.13, by version range2017-04-18
vulnerable: 3.0.0 ... 3.0.9 (15 versions)
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.
- CVE-2017-5656HIGHCVSS 7.5EG 7.5fixed in 3.1.11 or 3.0.13, by version range2017-04-18
vulnerable: 3.0.0 ... 3.0.9 (15 versions)
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached toke…
- CVE-2022-46363HIGHCVSS 7.5EG 7.5fixed in 3.4.10 or 3.5.5, by version range2022-12-13
vulnerable: 3.5.0, 3.5.1, 3.5.2, 3.5.3, 3.5.4
A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing or code exfiltration. The vulnerability only applies when the CXFServlet is configured with both the static-resources…
- CVE-2022-46364CRITICALCVSS 9.8EG 9.8fixed in 3.4.10 or 3.5.5, by version range2022-12-13
vulnerable: 3.5.0, 3.5.1, 3.5.2, 3.5.3, 3.5.4
A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any t…
- CVE-2025-23184MEDIUMCVSS 5.9EG 5.9fixed in 3.5.10, 3.6.5 or 4.0.6, by version range2025-01-21
vulnerable: 4.0.0 ... 4.0.5 (6 versions)
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the fi…
- CVE-2025-48795MEDIUMCVSS 5.6EG 5.6fixed in 3.5.11, 3.6.6, 4.0.7 or 4.1.1, by version range2025-07-15
vulnerable: 4.1.0
Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file is read into memory and then logged. An attacker might be able to exploit this to cau…
- CVE-2026-49875CRITICALCVSS 9.8EG 9.8fixed in 4.2.2 or 4.1.7, by version range2026-06-12
vulnerable: 3.0.0 ... 4.1.6 (122 versions)
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgra…
- CVE-2026-50645HIGHCVSS 7.5EG 7.5fixed in 4.2.2, 4.1.7 or 3.6.12, by version range2026-06-12
vulnerable: 3.0.0 ... 3.6.9 (102 versions)
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgr…
Check whether org.apache.cxf:cxf-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.cxf:cxf-core CVEs against the assets you own.
Book a Demo →