PT-2026-108818 · Apache · Apache Cxf

·

CVE-2026-86463

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 4.2.4 Apache CXF versions prior to 4.1.9 Apache CXF versions prior to 3.6.13
Description The FIQL query parser contains a flaw in its operator search mechanism. When processing a long string that lacks an operator, the search pattern attempts numerous combinations, leading to excessive CPU consumption. This can be exploited by sending a crafted query to exhaust server resources, which may degrade performance or cause a denial of service for other requests.
Recommendations Upgrade to version 4.2.4. Upgrade to version 4.1.9. Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-86463

Affected Products

Apache Cxf