Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-57819PATCHED
apache · cxf

Apache CXF: No default restriction on the amount of form parameters per message

Description

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.

Affected Products

VendorProductVersions
apachecxf4.2.0, 4.0.0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachecxfcert_advisory90%
realobjectspdfreactorcert_advisory90%

References

  • https://lists.apache.org/thread/2n14mk01bjc3lrsyhzrkwy8h86289mov(vendor-advisory)

Related News (6 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (21 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [mittel] RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans les produits IBM (14 août 2026)
→ No new info (linked only)
Tier C
oss-security17d ago
CVE-2026-57819: Apache CXF: No default restriction on the amount of form parameters per message
→ No new info (linked only)
Tier B
BSI Advisories17d ago
[NEU] [mittel] Apache CXF: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-57819 | Apache CXF up to 3.6.11/4.1.7/4.2.2 Form Parameter resource consumption
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.2.34.1.83.6.12
CWECWE-400
PublishedAug 6, 2026
Last enriched17d ago
Trending Score38
Source articles6
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 47
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 40
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 40
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 38
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 38

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 6, 2026
Discovered by ZDM
Aug 6, 2026
Patch Available
Aug 7, 2026