Author: buildbot
Date: Thu Jun 11 16:43:09 2026
New Revision: 1093252
Log:
Production update by buildbot for cxf
Added:
websites/production/cxf/content/security-advisories.data/CVE-2026-50645.txt
Modified:
websites/production/cxf/content/cache/main.pageCache
websites/production/cxf/content/index.html
websites/production/cxf/content/security-advisories.html
Modified: websites/production/cxf/content/cache/main.pageCache
==============================================================================
Binary file (source and/or target). No diff available.
Modified: websites/production/cxf/content/index.html
==============================================================================
--- websites/production/cxf/content/index.html Thu Jun 11 16:11:01 2026
(r1093251)
+++ websites/production/cxf/content/index.html Thu Jun 11 16:43:09 2026
(r1093252)
@@ -99,7 +99,7 @@ Apache CXF -- Index
<td height="100%">
<!-- Content -->
<div class="wiki-content">
-<div id="ConfluenceContent"><h1
id="Index-ApacheCXF™:AnOpen-SourceServicesFramework">Apache CXF™:
An Open-Source Services Framework</h1><h2
id="Index-Overview">Overview</h2><p>Apache CXF™ is an open source
services framework. CXF helps you build and develop services using frontend
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a
variety of transports such as HTTP, JMS or JBI.</p><h2
id="Index-News">News</h2><h3
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce
the availability of our latest patch releases! </p><p>Over 5 JIRA issues
were fixed for 4.2.2 and  4 JIRA issues were fixed for
4.1.7.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2
026 - Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team
is proud to announce the availability of our latest patch
releases! </p><p>Over 15 JIRA issues were fixed for 4.2.1,  10 JIRA
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for
3.6.11.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE
issues, please see <a shape="rect"
href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16,
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache
CXF team is proud to announce the availability of our latest patch
releases! </p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues
were fixed for 4.1.5,  14 JIRA issues were fixed for 4.0.11, 8 JIRA issues
were fixed for 3.6.10.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>
.</p><h3 id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17,
2025 - Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team
is proud to announce the availability of our latest patch
releases! </p><p>Over 13 JIRA issues were fixed for 4.1.4,  11 JIRA
issues were fixed for 4.0.10, 12 JIRA issues were fixed for
3.6.9.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 -
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 10 JIRA
issues were fixed for 4.1.3 and 4.0.9, </p><p>6 JIRA issues were fixed for
3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt">https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>
Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 -
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 16 JIRA
issues were fixed for 4.1.2, </p><p>11 JIRA issues were fixed for 4.0.8,
10 JIRA issues were fixed for 3.6.7.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 -
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team
is proud to announce the availability of our latest patch releases!  Over
17 JIRA issues were fixed for 4.1.1, </p><p>14 JIRA issues were fixed for
4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA issues were fixed for
3.5.11.</p><p>Please note that the CXF 3.5.11 is the last release of CXF 3.5.x
serie
s</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0
released!</h3><p>The Apache CXF team is proud to announce the availability of
CXF 4.1.0!  The 4.1.0 is our first release to feature Jakarta EE 10
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for
4.1.0, </p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 -
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch releases!  Over 29
JIRA issues were fixed for 4.0.6, </p><p>25 JIRA issues were fixed for
3.6.5 and 18 JIRA issues were fixed for 3.5.10.</p><p>Downloads are
available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July
17, 2024 - Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF
team is proud to announce the availability of our latest patch releases! 
Over 19 JIRA issues were fixed for 4.0.5.</p><p>These releases contain fixes
for 3 different CVEs:</p><ul><li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 12, 2024 -
Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Ap
ache CXF team is proud to announce the availability of our latest patch
releases!  Over 28 JIRA issues were fixed for 4.0.4.</p><p>These releases
contain a fix for a new security issue: <a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 -
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2released!">June 12, 2023 - Apache
CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache CXF team is proud to announce
the availability of our latest patch r
eleases!  Over 7 JIRA issues were fixed for 4.0.2 and
3.6.1.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to
announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-Features">Features</h3><p>CXF includes a broad feature set, but it is
primarily focused on the following areas:</p><ul><li><strong>Web Services
Standards Support:</strong> CXF supports a variety of web service standards
including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy,
WS-ReliableMessaging, WS-Security, WS-SecurityPolicy, WS-SecureConverstation,
and WS-Trust (partial).</li><li><strong>Frontends:</strong> CXF supports a
variety of "frontend" program
ming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF JAX-WS support
includes some extensions to the standard that make it significantly easier to
use, compared to the reference implementation: It will automatically generate
code for request and response bean classes, and does not require a WSDL for
simple cases.</p><p>It also includes a "simple frontend" which allows creation
of clients and endpoints without annotations. CXF supports both contract first
development with WSDL and code first development starting from Java.</p><p>For
REST, CXF also supports a JAX-RS frontend.</p><ul><li><strong>Ease of
use:</strong> CXF is designed to be intuitive and easy to use. There are simple
APIs to quickly build code-first services, Maven plug-ins to make tooling
integration easy, JAX-WS API support, Spring 2.x XML support to make
configuration a snap, and much more.</li><li><strong>Binary and Legacy Protocol
Support:</strong> CXF has been designed to provide a pluggable architecture tha
t supports not only XML but also non-XML type bindings, such as JSON and
CORBA, in combination with any type of transport.</li></ul><p>To get started
using CXF, check out the <a shape="rect" href="download.html">downloads</a>,
the <a shape="rect" href="http://cxf.apache.org/docs/index.html">user's
guide</a>, or the <a shape="rect" href="mailing-lists.html">mailing lists</a>
to get more information!</p><h2 id="Index-Goals">Goals</h2><h3
id="Index-General">General</h3><ul><li>High
Performance</li><li>Extensible</li><li>Intuitive & Easy to Use</li></ul><h3
id="Index-SupportforStandards">Support for Standards</h3><h5
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=224"
rel="nofollow">JSR-224</a></li><li>Web Services Metadata for the Java Platform
- <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=181" rel="nofollow">JSR-181<
/a></li><li>JAX-RS - The Java API for RESTful Web Services - <a shape="rect"
class="external-link" href="http://jcp.org/en/jsr/detail?id=311"
rel="nofollow">JSR-311,</a> <a shape="rect" class="external-link"
href="https://jcp.org/en/jsr/detail?id=370"
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java
(SAAJ) - <a shape="rect" class="external-link"
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"
rel="nofollow">JSR-67</a></li></ul><h5
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web
Service Definition Language</li><li>Communication Security: WS-Security,
WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial
support)</li><li>Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message
Transmission Optimization Mechanism (MTOM)</li></ul><h5 id="Index-
OpenAPISpecification(OAS)Support">OpenAPI Specification (OAS)
Support</h5><ul><li>OAS 2.0 (classic Swagger specification)</li><li>OAS 3.0.x
(new revised specification)</li></ul><h3
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple
Transports, Protocol Bindings, Data Bindings, and
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via
the <a shape="rect" class="external-link"
href="http://camel.apache.org/camel-transport-for-cxf.html">Camel transport for
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP,
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans,
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON,
FastInfoset</li><li>Extensibility API allows additional bindings for CXF,
enabling additional message format support such as CORBA/IIOP</li></ul><h3
id="Index-FlexibleDeployment">Flexible Deployment</h3><ul><li>Lightweight
containers: deploy services in Jetty, Tomc
at or Spring-based containers</li><li>JBI integration: deploy as a service
engine in a JBI container such as ServiceMix, OpenESB or Petals</li><li>Java EE
integration: deploy services in Java EE application servers such as Apache
Geronimo, JOnAS, Redhat JBoss, OC4J, Oracle WebLogic, and IBM
WebSphere</li><li>Standalone Java client/server</li></ul><h3
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS
for RESTful clients</li><li>Support for wrapped and non-wrapped
styles</li><li>XML messaging API</li><li>Support for JavaScript and ECMAScript
4 XML (E4X) - both client and server</li><li>Support for CORBA</li><li>Support
for JBI with ServiceMix</li></ul><h3
id="Index-Tooling">Tooling</h3><ul><li>Generating Code: WSDL to Java, WSDL to
JavaSc
ript, Java to JavaScript</li><li>Generating WSDL: Java to WSDL, XSD to WSDL,
IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: WSDL to SOAP, WSDL to CORBA,
WSDL to service</li><li>Generating Support Files: WSDL to
IDL</li><li>Validating Files: WSDL Validation</li></ul><h2
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently
under heavy development. To get involved you can <a shape="rect"
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab
the code from the <a shape="rect" href="source-repository.html">Source
Repository</a>. You also need to read about <a shape="rect"
href="building.html">Building</a> CXF. For Eclipse users, you should read about
<a shape="rect" href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
+<div id="ConfluenceContent"><h1
id="Index-ApacheCXF™:AnOpen-SourceServicesFramework">Apache CXF™:
An Open-Source Services Framework</h1><h2
id="Index-Overview">Overview</h2><p>Apache CXF™ is an open source
services framework. CXF helps you build and develop services using frontend
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a
variety of transports such as HTTP, JMS or JBI.</p><h2
id="Index-News">News</h2><h3
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce
the availability of our latest patch releases! </p><p>Over 5 JIRA issues
were fixed for 4.2.2 and  4 JIRA issues were fixed for
4.1.7.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases contain fixes for multiple
CVE issues, please see <a sha
pe="rect" href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2026 -
Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 15 JIRA issues were fixed for 4.2.1,  10 JIRA
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for
3.6.11.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE
issues, please see <a shape="rect"
href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16,
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache
CXF team is proud to announce the availability of our latest patch
releases! </p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues
were fixed for 4.1.5,  14 JIRA iss
ues were fixed for 4.0.11, 8 JIRA issues were fixed for
3.6.10.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 2025 -
Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 13 JIRA issues were fixed for 4.1.4,  11 JIRA
issues were fixed for 4.0.10, 12 JIRA issues were fixed for
3.6.9.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 -
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 10 JIRA
issues were fixed for 4.1.3 and 4.0.9, </p><p>6 JIRA issues were fixed for
3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a shape="rect"
href="https:/
/cxf.apache.org/security-advisories.data/CVE-2025-48913.txt">https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 -
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 16 JIRA
issues were fixed for 4.1.2, </p><p>11 JIRA issues were fixed for 4.0.8,
10 JIRA issues were fixed for 3.6.7.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 -
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team
is proud to announce the availability of our latest patch releases!  Over
17 JIRA issues were fixed for 4.1.1, </p><p>14 JIRA issues were fixed for
4.0.7, 11 JIRA i
ssues were fixed for 3.6.6 and 5 JIRA issues were fixed for
3.5.11.</p><p>Please note that the CXF 3.5.11 is the last release of CXF 3.5.x
series</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0
released!</h3><p>The Apache CXF team is proud to announce the availability of
CXF 4.1.0!  The 4.1.0 is our first release to feature Jakarta EE 10
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for
4.1.0, </p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 -
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch releases!  Over 29
JIRA issues were fixed for 4.0.6, </p><p>25 JIRA issues were fixed for
3.6.5 and 18 JIRA issues were fixed for 3.5.10.</p><p>Down
loads are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July 17, 2024 -
Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 19 JIRA
issues were fixed for 4.0.5.</p><p>These releases contain fixes for 3 different
CVEs:</p><ul><li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.
</p><h3 id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March
12, 2024 - Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Apache CXF
team is proud to announce the availability of our latest patch releases! 
Over 28 JIRA issues were fixed for 4.0.4.</p><p>These releases contain a fix
for a new security issue: <a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 -
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2releas
ed!">June 12, 2023 - Apache CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache
CXF team is proud to announce the availability of our latest patch
releases!  Over 7 JIRA issues were fixed for 4.0.2 and
3.6.1.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to
announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-Features">Features</h3><p>CXF includes a broad feature set, but it is
primarily focused on the following areas:</p><ul><li><strong>Web Services
Standards Support:</strong> CXF supports a variety of web service standards
including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy,
WS-ReliableMessaging, WS-Security, WS-
SecurityPolicy, WS-SecureConverstation, and WS-Trust
(partial).</li><li><strong>Frontends:</strong> CXF supports a variety of
"frontend" programming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF
JAX-WS support includes some extensions to the standard that make it
significantly easier to use, compared to the reference implementation: It will
automatically generate code for request and response bean classes, and does not
require a WSDL for simple cases.</p><p>It also includes a "simple frontend"
which allows creation of clients and endpoints without annotations. CXF
supports both contract first development with WSDL and code first development
starting from Java.</p><p>For REST, CXF also supports a JAX-RS
frontend.</p><ul><li><strong>Ease of use:</strong> CXF is designed to be
intuitive and easy to use. There are simple APIs to quickly build code-first
services, Maven plug-ins to make tooling integration easy, JAX-WS API support,
Spring 2.x XML support to make configuration a
snap, and much more.</li><li><strong>Binary and Legacy Protocol
Support:</strong> CXF has been designed to provide a pluggable architecture
that supports not only XML but also non-XML type bindings, such as JSON and
CORBA, in combination with any type of transport.</li></ul><p>To get started
using CXF, check out the <a shape="rect" href="download.html">downloads</a>,
the <a shape="rect" href="http://cxf.apache.org/docs/index.html">user's
guide</a>, or the <a shape="rect" href="mailing-lists.html">mailing lists</a>
to get more information!</p><h2 id="Index-Goals">Goals</h2><h3
id="Index-General">General</h3><ul><li>High
Performance</li><li>Extensible</li><li>Intuitive & Easy to Use</li></ul><h3
id="Index-SupportforStandards">Support for Standards</h3><h5
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=224"
rel="nofollow">JSR-224</a></li><li>Web Se
rvices Metadata for the Java Platform - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=181"
rel="nofollow">JSR-181</a></li><li>JAX-RS - The Java API for RESTful Web
Services - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=311" rel="nofollow">JSR-311,</a> <a
shape="rect" class="external-link" href="https://jcp.org/en/jsr/detail?id=370"
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java
(SAAJ) - <a shape="rect" class="external-link"
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"
rel="nofollow">JSR-67</a></li></ul><h5
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web
Service Definition Language</li><li>Communication Security: WS-Security,
WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial s
upport)</li><li>Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message
Transmission Optimization Mechanism (MTOM)</li></ul><h5
id="Index-OpenAPISpecification(OAS)Support">OpenAPI Specification (OAS)
Support</h5><ul><li>OAS 2.0 (classic Swagger specification)</li><li>OAS 3.0.x
(new revised specification)</li></ul><h3
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple
Transports, Protocol Bindings, Data Bindings, and
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via
the <a shape="rect" class="external-link"
href="http://camel.apache.org/camel-transport-for-cxf.html">Camel transport for
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP,
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans,
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON,
FastInfoset</li><li>Extensibility API allows additional bindings for CXF,
enabling additional message format support such
as CORBA/IIOP</li></ul><h3 id="Index-FlexibleDeployment">Flexible
Deployment</h3><ul><li>Lightweight containers: deploy services in Jetty, Tomcat
or Spring-based containers</li><li>JBI integration: deploy as a service engine
in a JBI container such as ServiceMix, OpenESB or Petals</li><li>Java EE
integration: deploy services in Java EE application servers such as Apache
Geronimo, JOnAS, Redhat JBoss, OC4J, Oracle WebLogic, and IBM
WebSphere</li><li>Standalone Java client/server</li></ul><h3
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS
for RESTful clients</li><li>Support for wrapped and non-wrapped
styles</li><li>XML messaging API</li><li>Support for JavaScript and ECMAScript
4 XML (E4X) - both client and server</li><li>Support for
CORBA</li><li>Support for JBI with ServiceMix</li></ul><h3
id="Index-Tooling">Tooling</h3><ul><li>Generating Code: WSDL to Java, WSDL to
JavaScript, Java to JavaScript</li><li>Generating WSDL: Java to WSDL, XSD to
WSDL, IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: WSDL to SOAP, WSDL to
CORBA, WSDL to service</li><li>Generating Support Files: WSDL to
IDL</li><li>Validating Files: WSDL Validation</li></ul><h2
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently
under heavy development. To get involved you can <a shape="rect"
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab
the code from the <a shape="rect" href="source-repository.html">Source
Repository</a>. You also need to read about <a shape="rect"
href="building.html">Building</a> CXF. For Eclipse users, you should read about
<a shape="rect" href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
</div>
<!-- Content -->
</td>
Added:
websites/production/cxf/content/security-advisories.data/CVE-2026-50645.txt
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-50645.txt
Thu Jun 11 16:43:09 2026 (r1093252)
@@ -0,0 +1,17 @@
+CVE-2026-50645: Apache CXF: No restriction on attachment headers per message
+
+Severity: low
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-core) 4.2.0 before 4.2.2
+- Apache CXF (org.apache.cxf:cxf-core) before 4.1.7
+
+Description:
+
+There is no restriction on the amount of attachment headers that a message can
contain when being deserialized by Apache CXF, which can lead to uncontrolled
resource consumption or a denial of service attack. Users are recommended to
upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum
default of 500 attachments per message.
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-50645
Modified: websites/production/cxf/content/security-advisories.html
==============================================================================
--- websites/production/cxf/content/security-advisories.html Thu Jun 11
16:11:01 2026 (r1093251)
+++ websites/production/cxf/content/security-advisories.html Thu Jun 11
16:43:09 2026 (r1093252)
@@ -99,7 +99,7 @@ Apache CXF -- Security Advisories
<td height="100%">
<!-- Content -->
<div class="wiki-content">
-<div id="ConfluenceContent"><p><span style="color: rgb(36,41,47);">For
information on how to report a new security problem please
see<span> </span></span><a shape="rect" class="external-link"
href="https://www.apache.org/security/" style="text-decoration:
none;">here</a><span style="color:
rgb(36,41,47);">.<span> </span></span></p><h3
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2026-44417.txt?version=1&modificationDate=1779445819000&api=v2"
data-linked-resource-id="429064531" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-44417</a>: Apache
CXF:Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to
RCE)</li><li><a shape="rect" href="security-advi
sories.data/CVE-2026-44618.txt?version=1&modificationDate=1779445877000&api=v2"
data-linked-resource-id="429064532" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-44618</a>: Apache CXF: XXE
vulnerability in WS-Transfer functionality</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-44930.txt?version=1&modificationDate=1779445722000&api=v2"
data-linked-resource-id="429064529" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-44930</a>: Apache CXF:
LDAP Injectio
n vulnerability in XKMS LDAP Repository</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-49875.txt?version=1&modificationDate=1781192084000&api=v2"
data-linked-resource-id="430408836" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-49875</a>: Apache CXF: XML
External Entity (XXE) Injection in W3CMultiSchemaFactory and
EndpointReferenceUtils </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50623.txt?version=1&modificationDate=1781192231000&api=v2"
data-linked-resource-id="430408838" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data
-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50623</a>: Apache CXF:
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50627.txt?version=1&modificationDate=1781192281000&api=v2"
data-linked-resource-id="430408839" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50627</a>: Apache CXF:
OAuth2: Missing JWT Audience and Issuer Validation in Access Token
Validator</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50628.txt?version=1&modificationDate=1781192316000&api=v2"
data-linked-resource-id="430408840" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-reso
urce-default-alias="CVE-2026-50628.txt" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50628</a>: Apache CXF:
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50629.txt?version=1&modificationDate=1781192369000&api=v2"
data-linked-resource-id="430408842" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50629</a>: Apache CXF:
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50630.txt?version=1&modificationDate=1781192413000&api=v2"
data-linked-resource-id="4
30408843" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50630</a>: Apache CXF:
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm
Injection </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50631.txt?version=1&modificationDate=1781192445000&api=v2"
data-linked-resource-id="430408844" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50631</a>: Apache CXF:
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a
shape="rect" href="security-ad
visories.data/CVE-2026-50631.txt?version=1&modificationDate=1781192445000&api=v2"
data-linked-resource-id="430408844" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2026-50632</a>: Apache CXF:
JNDI Injection Vulnerability in JMSConfigFactory</li></ul><h3
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2025-23184.txt?version=2&modificationDate=1737381863000&api=v2"
data-linked-resource-id="340036025" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502" data-linked-resource-container-ver
sion="58">CVE-2025-23184</a>: Apache CXF: Denial of Service vulnerability with
temporary files </li><li><a shape="rect"
href="security-advisories.data/CVE-2025-48795.txt?version=1&modificationDate=1752578416000&api=v2"
data-linked-resource-id="373886120" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-48795.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2025-48795</a>: Apache CXF:
Denial of Service and sensitive data exposure in logs </li><li><a
shape="rect"
href="security-advisories.data/CVE-2025-48913.txt?version=1&modificationDate=1754576095000&api=v2"
data-linked-resource-id="373887565" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text
File" data-linked-resource-con
tent-type="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2025-48913</a>: Apache CXF:
Untrusted JMS configuration can lead to RCE </li></ul><h3
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2024-28752.txt?version=2&modificationDate=1710431346000&api=v2"
data-linked-resource-id="296290905" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2024-28752</a>: Apache CXF SSRF
Vulnerability using the Aegis databinding </li><li><a shape="rect"
href="security-advisories.data/CVE-2024-29736.txt?version=1&modificationDate=1721314668000&api=v2"
data-linked-resource-id="315493016" data-linked-resource-version="1" data-linke
d-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2024-29736</a>: SSRF
vulnerability via WADL stylesheet parameter</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-32007.txt?version=1&modificationDate=1721314761000&api=v2"
data-linked-resource-id="315493017" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2024-32007</a>: Apache CXF
Denial of Service vulnerability in JOSE</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-41172.txt?version=1&modificationDate=1721314821000&api=v2"
data-linked-resource
-id="315493018" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2024-41172</a>: Unrestricted
memory consumption in CXF HTTP clients</li></ul><h3
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2022-46363.txt?version=1&modificationDate=1670942001000&api=v2"
data-linked-resource-id="235836918" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2022-46363</a>: Apache CXF
directory listing / code exfiltration</li><li><a shape="rect" href="security-a
dvisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944473000&api=v2"
data-linked-resource-id="235836926" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2022-46364</a>: Apache CXF SSRF
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&modificationDate=1623835370000&api=v2"
data-linked-resource-id="181310680" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-30468.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2021-304
68</a>: Apache CXF Denial of service vulnerability in parsing JSON via
JsonMapObjectReaderWriter</li><li><a shape="rect"
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&modificationDate=1617355743000&api=v2"
data-linked-resource-id="177049091" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-22696.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2021-22696</a>: OAuth 2
authorization service vulnerable to DDos attacks</li></ul><h3
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&modificationDate=1605183671000&api=v2"
data-linked-resource-id="165225095" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-13954.txt.asc" dat
a-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2020-13954</a>: Apache CXF
Reflected XSS in the services listing page via the styleSheetPath</li><li><a
shape="rect"
href="security-advisories.data/CVE-2020-1954.txt.asc?version=1&modificationDate=1585730169000&api=v2"
data-linked-resource-id="148645097" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2020-1954</a>: Apache CXF JMX
Integration is vulnerable to a MITM attack</li></ul><h3
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&modificationDate=1584610519000&api=v2"
data-linked-r
esource-id="145722246" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-17573.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2019-17573</a>: Apache CXF
Reflected XSS in the services listing page</li><li><a shape="rect"
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&modificationDate=1579178393000&api=v2"
data-linked-resource-id="145722244" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12423.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2019-12423</a>: Apache CXF
OpenId Connect JWK Keys service returns private/secret credentials if
configured with a jwk keystore</li><li
><a shape="rect"
>href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&modificationDate=1572961201000&api=v2"
> data-linked-resource-id="135859612" data-linked-resource-version="2"
>data-linked-resource-type="attachment"
>data-linked-resource-default-alias="CVE-2019-12419.txt.asc"
>data-nice-type="Text File" data-linked-resource-content-type="text/plain"
>data-linked-resource-container-id="27837502"
>data-linked-resource-container-version="58">CVE-2019-12419</a>: Apache CXF
>OpenId Connect token service does not properly validate the
>clientId</li><li><a shape="rect"
>href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&modificationDate=1572957147000&api=v2"
> data-linked-resource-id="135859607" data-linked-resource-version="1"
>data-linked-resource-type="attachment"
>data-linked-resource-default-alias="CVE-2019-12406.txt.asc"
>data-nice-type="Text File" data-linked-resource-content-type="text/plain"
>data-linked-resource-container-id="27837502" data-linked-reso
urce-container-version="58">CVE-2019-12406</a>: Apache CXF does not restrict
the number of message attachments</li></ul><h3
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&modificationDate=1530184663000&api=v2"
data-linked-resource-id="87296645" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2018-8039</a>: Apache CXF TLS
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&modificationDate=1530712328000&api=v2"
data-linked-resource-id="87297524" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-resource-default-
alias="CVE-2018-8038.txt.asc" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2018-8038</a>: Apache CXF Fediz
is vulnerable to DTD based XML attacks</li></ul><h3
id="SecurityAdvisories-2017">2017</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&modificationDate=1512037276000&api=v2"
data-linked-resource-id="74688816" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12631.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2017-12631</a>: CSRF
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&modificationDate=1510661632000&api=v
2" data-linked-resource-id="74687100" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12624.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2017-12624</a>: Apache CXF web
services that process attachments are vulnerable to Denial of Service (DoS)
attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&modificationDate=1494949377000&api=v2"
data-linked-resource-id="70255583" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2017-7662</a>: The Apache CXF
Fediz OIDC Client Registration Service is vulne
rable to CSRF attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&modificationDate=1494949364000&api=v2"
data-linked-resource-id="70255582" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7661.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2017-7661</a>: The Apache CXF
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113000&api=v2"
data-linked-resource-id="69406543" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837
502" data-linked-resource-container-version="58">CVE-2017-5656</a>: Apache
CXF's STSClient uses a flawed way of caching tokens that are associated with
delegation tokens.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&modificationDate=1492515074000&api=v2"
data-linked-resource-id="69406542" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2017-5653</a>: Apache CXF
JAX-RS XML Security streaming clients do not validate that the service response
was signed or encrypted.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&modificationDate=1487590374000&api=v2"
data-linked-resource-id="68715428" data-linked-resource-version="1"
data-linked-resource-type=
"attachment" data-linked-resource-default-alias="CVE-2017-3156.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2017-3156</a>: Apache CXF
OAuth2 Hawk and JOSE MAC Validation code is vulnerable to the timing
attacks</li></ul><h3 id="SecurityAdvisories-2016">2016</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635454" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2016-8739</a>: Atom entity
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect"
href="security-advisories.data/CVE-
2016-6812.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635455" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2016-6812</a>: XSS risk in
Apache CXF FormattedServiceListWriter when a request URL contains matrix
parameters</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&modificationDate=1473350153000&api=v2"
data-linked-resource-id="65869472" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2016-4464</
a>: Apache CXF Fediz application plugins do not match the SAML
AudienceRestriction values against the list of configured audience
URIs</li></ul><h3 id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&modificationDate=1447433340000&api=v2"
data-linked-resource-id="61328642" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2015-5253</a>: Apache CXF SAML
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&modificationDate=1440598018000&api=v2"
data-linked-resource-id="61316328" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-resource-d
efault-alias="CVE-2015-5175.txt.asc" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2015-5175</a>: Apache CXF Fediz
application plugins are vulnerable to Denial of Service (DoS)
attacks</li></ul><h3 id="SecurityAdvisories-2014">2014</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&modificationDate=1419245371000&api=v2"
data-linked-resource-id="51183657" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-3577</a>: Apache CXF SSL
hostname verification bypass</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&modificationDate=141874
0474000&api=v2" data-linked-resource-id="50561078"
data-linked-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">Note on CVE-2014-3566</a>: SSL 3.0
support in Apache CXF, aka the "POODLE" attack.</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&modificationDate=1414169368000&api=v2"
data-linked-resource-id="47743195" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-3623</a>: Apache CXF does
not properly enforce the security semantics of SAML SubjectConfirma
tion methods when used with the TransportBinding</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&modificationDate=1414169326000&api=v2"
data-linked-resource-id="47743194" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3584.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-3584</a>: Apache CXF
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS)
attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&modificationDate=1398873370000&api=v2"
data-linked-resource-id="40895138" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data-linke
d-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-0109</a>: HTML content
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&modificationDate=1398873378000&api=v2"
data-linked-resource-id="40895139" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-0110</a>: Large invalid
content could cause temporary space to fill</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&modificationDate=1398873385000&api=v2"
data-linked-resource-id="40895140" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0034.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-0034</a>: The
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a
shape="rect"
href="security-advisories.data/CVE-2014-0035.txt.asc?version=1&modificationDate=1398873391000&api=v2"
data-linked-resource-id="40895141" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2014-0035</a>: UsernameTokens
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&modificationDate=1372324301000&api
=v2" data-linked-resource-id="33095710" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="58">CVE-2013-2160</a> - Denial of
Service Attacks on Apache CXF</li><li><a shape="rect"
href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML Encryption backwards
compatibility attack on Apache CXF.</li><li><a shape="rect"
href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication bypass in the case
of WS-SecurityPolicy enabled plaintext UsernameTokens.</li></ul><h3
id="SecurityAdvisories-2012">2012</h3><ul><li><a shape="rect"
href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor always allows
HTTP Get requests from browser.</li><li><a shape="rect"
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher
attack against dis
tributed symmetric key in WS-Security.</li><li><a shape="rect"
href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is vulnerable to SOAP
Action spoofing attacks on Document Literal web services.</li><li><a
shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> - Apache CXF does not
verify that elements were signed or encrypted by a particular Supporting
Token.</li><li><a shape="rect" href="cve-2012-2378.html">CVE-2012-2378</a> -
Apache CXF does not pick up some child policies of WS-SecurityPolicy 1.1
SupportingToken policy assertions on the client side.</li><li><a shape="rect"
href="note-on-cve-2011-1096.html">Note on CVE-2011-1096</a> - XML Encryption
flaw / Character pattern encoding attack.</li><li><a shape="rect"
href="cve-2012-0803.html">CVE-2012-0803</a> - Apache CXF does not validate
UsernameToken policies correctly.</li></ul><h3
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect"
class="external-link" href="http://svn.apache.org/repos/asf/cxf/trunk/security/
CVE-2010-2076.pdf">CVE-2010-2076</a> - DTD based XML attacks.</li></ul><p><br
clear="none"></p></div>
+<div id="ConfluenceContent"><p><span style="color: rgb(36,41,47);">For
information on how to report a new security problem please
see<span> </span></span><a shape="rect" class="external-link"
href="https://www.apache.org/security/" style="text-decoration:
none;">here</a><span style="color:
rgb(36,41,47);">.<span> </span></span></p><h3
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2026-44417.txt?version=1&modificationDate=1779445819000&api=v2"
data-linked-resource-id="429064531" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-44417</a>: Apache
CXF:Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to
RCE)</li><li><a shape="rect" href="security-advi
sories.data/CVE-2026-44618.txt?version=1&modificationDate=1779445877000&api=v2"
data-linked-resource-id="429064532" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-44618</a>: Apache CXF: XXE
vulnerability in WS-Transfer functionality</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-44930.txt?version=1&modificationDate=1779445722000&api=v2"
data-linked-resource-id="429064529" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-44930</a>: Apache CXF:
LDAP Injectio
n vulnerability in XKMS LDAP Repository</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-49875.txt?version=1&modificationDate=1781192084000&api=v2"
data-linked-resource-id="430408836" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-49875</a>: Apache CXF: XML
External Entity (XXE) Injection in W3CMultiSchemaFactory and
EndpointReferenceUtils </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50623.txt?version=1&modificationDate=1781192231000&api=v2"
data-linked-resource-id="430408838" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data
-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50623</a>: Apache CXF:
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50627.txt?version=1&modificationDate=1781192281000&api=v2"
data-linked-resource-id="430408839" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50627</a>: Apache CXF:
OAuth2: Missing JWT Audience and Issuer Validation in Access Token
Validator</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50628.txt?version=1&modificationDate=1781192316000&api=v2"
data-linked-resource-id="430408840" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-reso
urce-default-alias="CVE-2026-50628.txt" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50628</a>: Apache CXF:
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50629.txt?version=1&modificationDate=1781192369000&api=v2"
data-linked-resource-id="430408842" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50629</a>: Apache CXF:
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50630.txt?version=1&modificationDate=1781192413000&api=v2"
data-linked-resource-id="4
30408843" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50630</a>: Apache CXF:
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm
Injection </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50631.txt?version=1&modificationDate=1781192445000&api=v2"
data-linked-resource-id="430408844" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50631</a>: Apache CXF:
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a
shape="rect" href="security-ad
visories.data/CVE-2026-50631.txt?version=1&modificationDate=1781192445000&api=v2"
data-linked-resource-id="430408844" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50632</a>: Apache CXF:
JNDI Injection Vulnerability in JMSConfigFactory</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50633.txt?version=1&modificationDate=1781192513000&api=v2"
data-linked-resource-id="430408847" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50633</a>: Apache CXF:
JNDI Inje
ction vulnerability in DispatchMDBMessageListenerImpl</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50633.txt?version=1&modificationDate=1781192513000&api=v2"
data-linked-resource-id="430408847" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50634</a>: Apache CXF: WS
JSON request filter trusts metadata from an unvalidated first signature
entry</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50634.txt?version=1&modificationDate=1781192545000&api=v2"
data-linked-resource-id="430408848" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50634.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" dat
a-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2026-50645</a>: Apache CXF: No
restriction on attachment headers per message</li></ul><h3
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2025-23184.txt?version=2&modificationDate=1737381863000&api=v2"
data-linked-resource-id="340036025" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2025-23184</a>: Apache CXF:
Denial of Service vulnerability with temporary files </li><li><a
shape="rect"
href="security-advisories.data/CVE-2025-48795.txt?version=1&modificationDate=1752578416000&api=v2"
data-linked-resource-id="373886120" data-linked-resource-version="1"
data-linked-resource-type="att
achment" data-linked-resource-default-alias="CVE-2025-48795.txt"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2025-48795</a>: Apache CXF:
Denial of Service and sensitive data exposure in logs </li><li><a
shape="rect"
href="security-advisories.data/CVE-2025-48913.txt?version=1&modificationDate=1754576095000&api=v2"
data-linked-resource-id="373887565" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2025-48913</a>: Apache CXF:
Untrusted JMS configuration can lead to RCE </li></ul><h3
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2024-28752.txt?version=2&am
p;modificationDate=1710431346000&api=v2"
data-linked-resource-id="296290905" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2024-28752</a>: Apache CXF SSRF
Vulnerability using the Aegis databinding </li><li><a shape="rect"
href="security-advisories.data/CVE-2024-29736.txt?version=1&modificationDate=1721314668000&api=v2"
data-linked-resource-id="315493016" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2024-29736</a>: SSRF
vulnerability via WADL stylesheet parameter</li><li><a sha
pe="rect"
href="security-advisories.data/CVE-2024-32007.txt?version=1&modificationDate=1721314761000&api=v2"
data-linked-resource-id="315493017" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2024-32007</a>: Apache CXF
Denial of Service vulnerability in JOSE</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-41172.txt?version=1&modificationDate=1721314821000&api=v2"
data-linked-resource-id="315493018" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2024-41172</a>: Unre
stricted memory consumption in CXF HTTP clients</li></ul><h3
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2022-46363.txt?version=1&modificationDate=1670942001000&api=v2"
data-linked-resource-id="235836918" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2022-46363</a>: Apache CXF
directory listing / code exfiltration</li><li><a shape="rect"
href="security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944473000&api=v2"
data-linked-resource-id="235836926" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" da
ta-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2022-46364</a>: Apache CXF SSRF
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&modificationDate=1623835370000&api=v2"
data-linked-resource-id="181310680" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-30468.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2021-30468</a>: Apache CXF
Denial of service vulnerability in parsing JSON via
JsonMapObjectReaderWriter</li><li><a shape="rect"
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&modificationDate=1617355743000&api=v2"
data-linked-resource-id="177049091" data-linked-resource-version="1"
data-linked-resource-type="att
achment" data-linked-resource-default-alias="CVE-2021-22696.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2021-22696</a>: OAuth 2
authorization service vulnerable to DDos attacks</li></ul><h3
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&modificationDate=1605183671000&api=v2"
data-linked-resource-id="165225095" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-13954.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2020-13954</a>: Apache CXF
Reflected XSS in the services listing page via the styleSheetPath</li><li><a
shape="rect" href="security-advisories.data/CVE-2020-1954.txt.a
sc?version=1&modificationDate=1585730169000&api=v2"
data-linked-resource-id="148645097" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2020-1954</a>: Apache CXF JMX
Integration is vulnerable to a MITM attack</li></ul><h3
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&modificationDate=1584610519000&api=v2"
data-linked-resource-id="145722246" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-17573.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2019-1757
3</a>: Apache CXF Reflected XSS in the services listing page</li><li><a
shape="rect"
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&modificationDate=1579178393000&api=v2"
data-linked-resource-id="145722244" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12423.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2019-12423</a>: Apache CXF
OpenId Connect JWK Keys service returns private/secret credentials if
configured with a jwk keystore</li><li><a shape="rect"
href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&modificationDate=1572961201000&api=v2"
data-linked-resource-id="135859612" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12419.txt.asc"
data-nice-type="Text File" data-lin
ked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2019-12419</a>: Apache CXF
OpenId Connect token service does not properly validate the clientId</li><li><a
shape="rect"
href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&modificationDate=1572957147000&api=v2"
data-linked-resource-id="135859607" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12406.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2019-12406</a>: Apache CXF does
not restrict the number of message attachments</li></ul><h3
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&modificationDate=1530184663000&api=v2"
data-linked-resource-id="87296645"
data-linked-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2018-8039</a>: Apache CXF TLS
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&modificationDate=1530712328000&api=v2"
data-linked-resource-id="87297524" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8038.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2018-8038</a>: Apache CXF Fediz
is vulnerable to DTD based XML attacks</li></ul><h3
id="SecurityAdvisories-2017">2017</h3><ul><li><a s
hape="rect"
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&modificationDate=1512037276000&api=v2"
data-linked-resource-id="74688816" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12631.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2017-12631</a>: CSRF
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&modificationDate=1510661632000&api=v2"
data-linked-resource-id="74687100" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12624.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60
">CVE-2017-12624</a>: Apache CXF web services that process attachments are
vulnerable to Denial of Service (DoS) attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&modificationDate=1494949377000&api=v2"
data-linked-resource-id="70255583" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2017-7662</a>: The Apache CXF
Fediz OIDC Client Registration Service is vulnerable to CSRF
attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&modificationDate=1494949364000&api=v2"
data-linked-resource-id="70255582" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7661.txt.asc" data-nic
e-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2017-7661</a>: The Apache CXF
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113000&api=v2"
data-linked-resource-id="69406543" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2017-5656</a>: Apache CXF's
STSClient uses a flawed way of caching tokens that are associated with
delegation tokens.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&modificationDate=1492515074000&api=v2"
data-linked-resource-id="6
9406542" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2017-5653</a>: Apache CXF
JAX-RS XML Security streaming clients do not validate that the service response
was signed or encrypted.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&modificationDate=1487590374000&api=v2"
data-linked-resource-id="68715428" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-3156.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2017-3156</a>: Apache CXF
OAuth2 Hawk and JOSE MAC Validation code is vulnerable to the timi
ng attacks</li></ul><h3 id="SecurityAdvisories-2016">2016</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635454" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2016-8739</a>: Atom entity
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-6812.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635455" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data-linked-reso
urce-container-id="27837502"
data-linked-resource-container-version="60">CVE-2016-6812</a>: XSS risk in
Apache CXF FormattedServiceListWriter when a request URL contains matrix
parameters</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&modificationDate=1473350153000&api=v2"
data-linked-resource-id="65869472" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2016-4464</a>: Apache CXF Fediz
application plugins do not match the SAML AudienceRestriction values against
the list of configured audience URIs</li></ul><h3
id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&modificationDate=1447433340000&api=v2"
data-linked
-resource-id="61328642" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2015-5253</a>: Apache CXF SAML
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&modificationDate=1440598018000&api=v2"
data-linked-resource-id="61316328" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5175.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2015-5175</a>: Apache CXF Fediz
application plugins are vulnerable to Denial of Service (DoS)
attacks</li></ul><h3 id="Security
Advisories-2014">2014</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&modificationDate=1419245371000&api=v2"
data-linked-resource-id="51183657" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-3577</a>: Apache CXF SSL
hostname verification bypass</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&modificationDate=1418740474000&api=v2"
data-linked-resource-id="50561078" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502" data-linked-resource-conta
iner-version="60">Note on CVE-2014-3566</a>: SSL 3.0 support in Apache CXF,
aka the "POODLE" attack.</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&modificationDate=1414169368000&api=v2"
data-linked-resource-id="47743195" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-3623</a>: Apache CXF does
not properly enforce the security semantics of SAML SubjectConfirmation methods
when used with the TransportBinding</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&modificationDate=1414169326000&api=v2"
data-linked-resource-id="47743194" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-resource-default-alias="CVE-2
014-3584.txt.asc" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-3584</a>: Apache CXF
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS)
attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&modificationDate=1398873370000&api=v2"
data-linked-resource-id="40895138" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-0109</a>: HTML content
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&modificationDate=1398873378000&api=v2"
data-linked-resource-id="40895139" data
-linked-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-0110</a>: Large invalid
content could cause temporary space to fill</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&modificationDate=1398873385000&api=v2"
data-linked-resource-id="40895140" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0034.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-0034</a>: The
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a
shape="rect" href="security-advisories.data/CVE-2014-0035.txt.asc?v
ersion=1&modificationDate=1398873391000&api=v2"
data-linked-resource-id="40895141" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="60">CVE-2014-0035</a>: UsernameTokens
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&modificationDate=1372324301000&api=v2"
data-linked-resource-id="33095710" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="6
0">CVE-2013-2160</a> - Denial of Service Attacks on Apache CXF</li><li><a
shape="rect" href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML
Encryption backwards compatibility attack on Apache CXF.</li><li><a
shape="rect" href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication
bypass in the case of WS-SecurityPolicy enabled plaintext
UsernameTokens.</li></ul><h3 id="SecurityAdvisories-2012">2012</h3><ul><li><a
shape="rect" href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor
always allows HTTP Get requests from browser.</li><li><a shape="rect"
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher
attack against distributed symmetric key in WS-Security.</li><li><a
shape="rect" href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is
vulnerable to SOAP Action spoofing attacks on Document Literal web
services.</li><li><a shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> -
Apache CXF does not verify that elements were signed or encry
pted by a particular Supporting Token.</li><li><a shape="rect"
href="cve-2012-2378.html">CVE-2012-2378</a> - Apache CXF does not pick up some
child policies of WS-SecurityPolicy 1.1 SupportingToken policy assertions on
the client side.</li><li><a shape="rect" href="note-on-cve-2011-1096.html">Note
on CVE-2011-1096</a> - XML Encryption flaw / Character pattern encoding
attack.</li><li><a shape="rect" href="cve-2012-0803.html">CVE-2012-0803</a> -
Apache CXF does not validate UsernameToken policies correctly.</li></ul><h3
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect"
class="external-link"
href="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf">CVE-2010-2076</a>
- DTD based XML attacks.</li></ul><p><br clear="none"></p></div>
</div>
<!-- Content -->
</td>