An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 06 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. | |
| Title | Apache CXF: Denial of service via message header attachments | |
| Weaknesses | CWE-400 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-06T15:10:53.292Z
Reserved: 2026-07-21T08:59:30.596Z
Link: CVE-2026-64958
Updated: 2026-08-06T15:10:48.199Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T17:30:16Z