Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 09 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache cxf |
|
| Vendors & Products |
Apache
Apache cxf |
Fri, 09 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-400 |
Fri, 09 Oct 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue. | |
| Title | Apache CXF: The attachment header size and count limits can be bypassed, which allows denial of service through memory exhaustion. | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-09T11:07:52.472Z
Reserved: 2026-10-09T09:12:15.139Z
Link: CVE-2026-107937
No data.
Status : Undergoing Analysis
Published: 2026-10-09T11:17:02.107
Modified: 2026-10-09T16:33:39.007
Link: CVE-2026-107937
No data.
OpenCVE Enrichment
Updated: 2026-10-09T12:00:06Z