Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-54225PATCHED
apache · cxf

Apache CXF: Denial of Service attack via large attachments

Description

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.

Affected Products

VendorProductVersions
apachecxf4.2.0, 4.0.0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachecxfcert_advisory90%
realobjectspdfreactorcert_advisory90%

References

  • https://lists.apache.org/thread/h2bjqm6g58z0j6893qzh728kdtk1byfy(vendor-advisory)

Related News (6 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (21 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier C
oss-security17d ago
CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
→ No new info (linked only)
Tier B
BSI Advisories17d ago
[NEU] [mittel] Apache CXF: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-54225 | Apache CXF up to 3.6.11/4.1.7/4.2.2 attachment-max-size resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.2.34.1.83.6.12
CWECWE-770
PublishedAug 6, 2026
Last enriched17d ago
Trending Score38
Source articles6
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 47
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 40
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 40
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 38
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 38

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Aug 7, 2026