PT-2026-108811 · Apache · Apache Cxf

CVE-2026-107937

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 4.2.4 Apache CXF versions prior to 4.1.9 Apache CXF versions prior to 3.6.13
Description The parser for multipart/MTOM attachment part headers fails to strictly enforce the attachment-max-header-size and attachment-headers-max-count limits. The size limit is only applied to individual physical lines rather than the total value of headers built from continuation lines or repeated headers. Additionally, the count limit is only checked against distinct header names instead of the total number of header lines. A remote, unauthenticated attacker can exploit this by sending a multipart request containing excessively large folded or repeated part headers, leading to unbounded memory allocation and a denial of service.
Recommendations Upgrade to version 4.2.4. Upgrade to version 4.1.9. Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-107937

Affected Products

Apache Cxf