Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-64958PATCHED
apache · cxf

Apache CXF: Denial of service via message header attachments

Description

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected Products

VendorProductVersions
apachecxf4.2.0, 4.0.0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachecxfcert_advisory90%
realobjectspdfreactorcert_advisory90%

References

  • https://lists.apache.org/thread/trsnkxc2f21585zlt819blvchgl6oykb(vendor-advisory)

Related News (6 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (21 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier C
oss-security17d ago
CVE-2026-64958: Apache CXF: Denial of service via message header attachments
→ No new info (linked only)
Tier B
BSI Advisories17d ago
[NEU] [mittel] Apache CXF: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-64958 | Apache CXF up to 3.6.11/4.1.7/4.2.2 resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.2.34.1.83.6.12
CWECWE-400
PublishedAug 6, 2026
Last enriched17d ago
Trending Score38
Source articles6
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 47
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 40
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 40
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 38
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 38

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Aug 6, 2026