PT-2026-108818 · Apache · Apache Cxf
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Apache CXF versions prior to 4.2.4
Apache CXF versions prior to 4.1.9
Apache CXF versions prior to 3.6.13
Description
The FIQL query parser contains a flaw in its operator search mechanism. When processing a long string that lacks an operator, the search pattern attempts numerous combinations, leading to excessive CPU consumption. This can be exploited by sending a crafted query to exhaust server resources, which may degrade performance or cause a denial of service for other requests.
Recommendations
Upgrade to version 4.2.4.
Upgrade to version 4.1.9.
Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Cxf