Author: buildbot
Date: Thu Jun 11 16:43:09 2026
New Revision: 1093252

Log:
Production update by buildbot for cxf

Added:
   websites/production/cxf/content/security-advisories.data/CVE-2026-50645.txt
Modified:
   websites/production/cxf/content/cache/main.pageCache
   websites/production/cxf/content/index.html
   websites/production/cxf/content/security-advisories.html

Modified: websites/production/cxf/content/cache/main.pageCache
==============================================================================
Binary file (source and/or target). No diff available.

Modified: websites/production/cxf/content/index.html
==============================================================================
--- websites/production/cxf/content/index.html  Thu Jun 11 16:11:01 2026        
(r1093251)
+++ websites/production/cxf/content/index.html  Thu Jun 11 16:43:09 2026        
(r1093252)
@@ -99,7 +99,7 @@ Apache CXF -- Index
          <td height="100%">
            <!-- Content -->
            <div class="wiki-content">
-<div id="ConfluenceContent"><h1 
id="Index-ApacheCXF&#8482;:AnOpen-SourceServicesFramework">Apache CXF&#8482;: 
An Open-Source Services Framework</h1><h2 
id="Index-Overview">Overview</h2><p>Apache CXF&#8482; is an open source 
services framework. CXF helps you build and develop services using frontend 
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of 
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a 
variety of transports such as HTTP, JMS or JBI.</p><h2 
id="Index-News">News</h2><h3 
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache 
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce 
the availability of our latest patch releases!&#160;</p><p>Over 5 JIRA issues 
were fixed for 4.2.2 and&#160; 4 JIRA issues were fixed for 
4.1.7.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2
 026 - Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team 
is proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 15 JIRA issues were fixed for 4.2.1, &#160;10 JIRA 
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for 
3.6.11.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE 
issues, please see&#160;<a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16, 
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache 
CXF team is proud to announce the availability of our latest patch 
releases!&#160;</p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues 
were fixed for 4.1.5, &#160;14 JIRA issues were fixed for 4.0.11, 8 JIRA issues 
were fixed for 3.6.10.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>
 .</p><h3 id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 
2025 - Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team 
is proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 13 JIRA issues were fixed for 4.1.4,&#160; 11 JIRA 
issues were fixed for 4.0.10, 12 JIRA issues were fixed for 
3.6.9.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 - 
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 10 JIRA 
issues were fixed for 4.1.3 and 4.0.9,&#160;</p><p>6 JIRA issues were fixed for 
3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt";>https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>
 Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 - 
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 16 JIRA 
issues were fixed for 4.1.2,&#160;</p><p>11 JIRA issues were fixed for 4.0.8, 
10 JIRA issues were fixed for 3.6.7.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 - 
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team 
is proud to announce the availability of our latest patch releases!&#160; Over 
17 JIRA issues were fixed for 4.1.1,&#160;</p><p>14 JIRA issues were fixed for 
4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA issues were fixed for 
3.5.11.</p><p>Please note that the CXF 3.5.11 is the last release of CXF 3.5.x 
serie
 s</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0 
released!</h3><p>The Apache CXF team is proud to announce the availability of 
CXF 4.1.0! &#160;The 4.1.0 is our first release to feature Jakarta EE 10 
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for 
4.1.0,&#160;</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 - 
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch releases!&#160; Over 29 
JIRA issues were fixed for 4.0.6,&#160;</p><p>25 JIRA issues were fixed for 
3.6.5 and 18 JIRA issues were fixed for 3.5.10.</p><p>Downloads are 
available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July
  17, 2024 - Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF 
team is proud to announce the availability of our latest patch releases!&#160; 
Over 19 JIRA issues were fixed for 4.0.5.</p><p>These releases contain fixes 
for 3 different CVEs:</p><ul><li><a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 12, 2024 - 
Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Ap
 ache CXF team is proud to announce the availability of our latest patch 
releases!&#160; Over 28 JIRA issues were fixed for 4.0.4.</p><p>These releases 
contain a fix for a new security issue: <a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 - 
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2released!">June 12, 2023 - Apache 
CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache CXF team is proud to announce 
the availability of our latest patch r
 eleases!&#160; Over 7 JIRA issues were fixed for 4.0.2 and 
3.6.1.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache 
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to 
announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Features">Features</h3><p>CXF includes a broad feature set, but it is 
primarily focused on the following areas:</p><ul><li><strong>Web Services 
Standards Support:</strong> CXF supports a variety of web service standards 
including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy, 
WS-ReliableMessaging, WS-Security, WS-SecurityPolicy, WS-SecureConverstation, 
and WS-Trust (partial).</li><li><strong>Frontends:</strong> CXF supports a 
variety of "frontend" program
 ming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF JAX-WS support 
includes some extensions to the standard that make it significantly easier to 
use, compared to the reference implementation: It will automatically generate 
code for request and response bean classes, and does not require a WSDL for 
simple cases.</p><p>It also includes a "simple frontend" which allows creation 
of clients and endpoints without annotations. CXF supports both contract first 
development with WSDL and code first development starting from Java.</p><p>For 
REST, CXF also supports a JAX-RS frontend.</p><ul><li><strong>Ease of 
use:</strong> CXF is designed to be intuitive and easy to use. There are simple 
APIs to quickly build code-first services, Maven plug-ins to make tooling 
integration easy, JAX-WS API support, Spring 2.x XML support to make 
configuration a snap, and much more.</li><li><strong>Binary and Legacy Protocol 
Support:</strong> CXF has been designed to provide a pluggable architecture tha
 t supports not only XML but also non-XML type bindings, such as JSON and 
CORBA, in combination with any type of transport.</li></ul><p>To get started 
using CXF, check out the <a shape="rect" href="download.html">downloads</a>, 
the <a shape="rect" href="http://cxf.apache.org/docs/index.html";>user's 
guide</a>, or the <a shape="rect" href="mailing-lists.html">mailing lists</a> 
to get more information!</p><h2 id="Index-Goals">Goals</h2><h3 
id="Index-General">General</h3><ul><li>High 
Performance</li><li>Extensible</li><li>Intuitive &amp; Easy to Use</li></ul><h3 
id="Index-SupportforStandards">Support for Standards</h3><h5 
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based 
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=224"; 
rel="nofollow">JSR-224</a></li><li>Web Services Metadata for the Java Platform 
- <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=181"; rel="nofollow">JSR-181<
 /a></li><li>JAX-RS - The Java API for RESTful Web Services - <a shape="rect" 
class="external-link" href="http://jcp.org/en/jsr/detail?id=311"; 
rel="nofollow">JSR-311,</a> <a shape="rect" class="external-link" 
href="https://jcp.org/en/jsr/detail?id=370"; 
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java 
(SAAJ) - <a shape="rect" class="external-link" 
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"; 
rel="nofollow">JSR-67</a></li></ul><h5 
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications 
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of 
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web 
Service Definition Language</li><li>Communication Security: WS-Security, 
WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial 
support)</li><li>Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message 
Transmission Optimization Mechanism (MTOM)</li></ul><h5 id="Index-
 OpenAPISpecification(OAS)Support">OpenAPI Specification (OAS) 
Support</h5><ul><li>OAS 2.0 (classic Swagger specification)</li><li>OAS 3.0.x 
(new revised specification)</li></ul><h3 
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple 
Transports, Protocol Bindings, Data Bindings, and 
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via 
the <a shape="rect" class="external-link" 
href="http://camel.apache.org/camel-transport-for-cxf.html";>Camel transport for 
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP, 
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans, 
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON, 
FastInfoset</li><li>Extensibility API allows additional bindings for CXF, 
enabling additional message format support such as CORBA/IIOP</li></ul><h3 
id="Index-FlexibleDeployment">Flexible Deployment</h3><ul><li>Lightweight 
containers: deploy services in Jetty, Tomc
 at or Spring-based containers</li><li>JBI integration: deploy as a service 
engine in a JBI container such as ServiceMix, OpenESB or Petals</li><li>Java EE 
integration: deploy services in Java EE application servers such as Apache 
Geronimo, JOnAS, Redhat JBoss, OC4J, Oracle WebLogic, and IBM 
WebSphere</li><li>Standalone Java client/server</li></ul><h3 
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple 
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server 
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way 
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS 
for RESTful clients</li><li>Support for wrapped and non-wrapped 
styles</li><li>XML messaging API</li><li>Support for JavaScript and ECMAScript 
4 XML (E4X) - both client and server</li><li>Support for CORBA</li><li>Support 
for JBI with ServiceMix</li></ul><h3 
id="Index-Tooling">Tooling</h3><ul><li>Generating Code: WSDL to Java, WSDL to 
JavaSc
 ript, Java to JavaScript</li><li>Generating WSDL: Java to WSDL, XSD to WSDL, 
IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: WSDL to SOAP, WSDL to CORBA, 
WSDL to service</li><li>Generating Support Files: WSDL to 
IDL</li><li>Validating Files: WSDL Validation</li></ul><h2 
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently 
under heavy development. To get involved you can <a shape="rect" 
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab 
the code from the <a shape="rect" href="source-repository.html">Source 
Repository</a>. You also need to read about <a shape="rect" 
href="building.html">Building</a> CXF. For Eclipse users, you should read about 
<a shape="rect" href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
+<div id="ConfluenceContent"><h1 
id="Index-ApacheCXF&#8482;:AnOpen-SourceServicesFramework">Apache CXF&#8482;: 
An Open-Source Services Framework</h1><h2 
id="Index-Overview">Overview</h2><p>Apache CXF&#8482; is an open source 
services framework. CXF helps you build and develop services using frontend 
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of 
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a 
variety of transports such as HTTP, JMS or JBI.</p><h2 
id="Index-News">News</h2><h3 
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache 
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce 
the availability of our latest patch releases!&#160;</p><p>Over 5 JIRA issues 
were fixed for 4.2.2 and&#160; 4 JIRA issues were fixed for 
4.1.7.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for multiple 
CVE issues, please see <a sha
 pe="rect" href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2026 - 
Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 15 JIRA issues were fixed for 4.2.1, &#160;10 JIRA 
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for 
3.6.11.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE 
issues, please see&#160;<a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16, 
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache 
CXF team is proud to announce the availability of our latest patch 
releases!&#160;</p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues 
were fixed for 4.1.5, &#160;14 JIRA iss
 ues were fixed for 4.0.11, 8 JIRA issues were fixed for 
3.6.10.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 2025 - 
Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 13 JIRA issues were fixed for 4.1.4,&#160; 11 JIRA 
issues were fixed for 4.0.10, 12 JIRA issues were fixed for 
3.6.9.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 - 
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 10 JIRA 
issues were fixed for 4.1.3 and 4.0.9,&#160;</p><p>6 JIRA issues were fixed for 
3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a shape="rect" 
href="https:/
 
/cxf.apache.org/security-advisories.data/CVE-2025-48913.txt">https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 - 
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 16 JIRA 
issues were fixed for 4.1.2,&#160;</p><p>11 JIRA issues were fixed for 4.0.8, 
10 JIRA issues were fixed for 3.6.7.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 - 
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team 
is proud to announce the availability of our latest patch releases!&#160; Over 
17 JIRA issues were fixed for 4.1.1,&#160;</p><p>14 JIRA issues were fixed for 
4.0.7, 11 JIRA i
 ssues were fixed for 3.6.6 and 5 JIRA issues were fixed for 
3.5.11.</p><p>Please note that the CXF 3.5.11 is the last release of CXF 3.5.x 
series</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0 
released!</h3><p>The Apache CXF team is proud to announce the availability of 
CXF 4.1.0! &#160;The 4.1.0 is our first release to feature Jakarta EE 10 
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for 
4.1.0,&#160;</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 - 
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch releases!&#160; Over 29 
JIRA issues were fixed for 4.0.6,&#160;</p><p>25 JIRA issues were fixed for 
3.6.5 and 18 JIRA issues were fixed for 3.5.10.</p><p>Down
 loads are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July 17, 2024 - 
Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 19 JIRA 
issues were fixed for 4.0.5.</p><p>These releases contain fixes for 3 different 
CVEs:</p><ul><li><a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.
 </p><h3 id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 
12, 2024 - Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Apache CXF 
team is proud to announce the availability of our latest patch releases!&#160; 
Over 28 JIRA issues were fixed for 4.0.4.</p><p>These releases contain a fix 
for a new security issue: <a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 - 
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2releas
 ed!">June 12, 2023 - Apache CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache 
CXF team is proud to announce the availability of our latest patch 
releases!&#160; Over 7 JIRA issues were fixed for 4.0.2 and 
3.6.1.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache 
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to 
announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Features">Features</h3><p>CXF includes a broad feature set, but it is 
primarily focused on the following areas:</p><ul><li><strong>Web Services 
Standards Support:</strong> CXF supports a variety of web service standards 
including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy, 
WS-ReliableMessaging, WS-Security, WS-
 SecurityPolicy, WS-SecureConverstation, and WS-Trust 
(partial).</li><li><strong>Frontends:</strong> CXF supports a variety of 
"frontend" programming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF 
JAX-WS support includes some extensions to the standard that make it 
significantly easier to use, compared to the reference implementation: It will 
automatically generate code for request and response bean classes, and does not 
require a WSDL for simple cases.</p><p>It also includes a "simple frontend" 
which allows creation of clients and endpoints without annotations. CXF 
supports both contract first development with WSDL and code first development 
starting from Java.</p><p>For REST, CXF also supports a JAX-RS 
frontend.</p><ul><li><strong>Ease of use:</strong> CXF is designed to be 
intuitive and easy to use. There are simple APIs to quickly build code-first 
services, Maven plug-ins to make tooling integration easy, JAX-WS API support, 
Spring 2.x XML support to make configuration a
  snap, and much more.</li><li><strong>Binary and Legacy Protocol 
Support:</strong> CXF has been designed to provide a pluggable architecture 
that supports not only XML but also non-XML type bindings, such as JSON and 
CORBA, in combination with any type of transport.</li></ul><p>To get started 
using CXF, check out the <a shape="rect" href="download.html">downloads</a>, 
the <a shape="rect" href="http://cxf.apache.org/docs/index.html";>user's 
guide</a>, or the <a shape="rect" href="mailing-lists.html">mailing lists</a> 
to get more information!</p><h2 id="Index-Goals">Goals</h2><h3 
id="Index-General">General</h3><ul><li>High 
Performance</li><li>Extensible</li><li>Intuitive &amp; Easy to Use</li></ul><h3 
id="Index-SupportforStandards">Support for Standards</h3><h5 
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based 
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=224"; 
rel="nofollow">JSR-224</a></li><li>Web Se
 rvices Metadata for the Java Platform - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=181"; 
rel="nofollow">JSR-181</a></li><li>JAX-RS - The Java API for RESTful Web 
Services - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=311"; rel="nofollow">JSR-311,</a> <a 
shape="rect" class="external-link" href="https://jcp.org/en/jsr/detail?id=370"; 
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java 
(SAAJ) - <a shape="rect" class="external-link" 
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"; 
rel="nofollow">JSR-67</a></li></ul><h5 
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications 
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of 
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web 
Service Definition Language</li><li>Communication Security: WS-Security, 
WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial s
 upport)</li><li>Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message 
Transmission Optimization Mechanism (MTOM)</li></ul><h5 
id="Index-OpenAPISpecification(OAS)Support">OpenAPI Specification (OAS) 
Support</h5><ul><li>OAS 2.0 (classic Swagger specification)</li><li>OAS 3.0.x 
(new revised specification)</li></ul><h3 
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple 
Transports, Protocol Bindings, Data Bindings, and 
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via 
the <a shape="rect" class="external-link" 
href="http://camel.apache.org/camel-transport-for-cxf.html";>Camel transport for 
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP, 
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans, 
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON, 
FastInfoset</li><li>Extensibility API allows additional bindings for CXF, 
enabling additional message format support such
  as CORBA/IIOP</li></ul><h3 id="Index-FlexibleDeployment">Flexible 
Deployment</h3><ul><li>Lightweight containers: deploy services in Jetty, Tomcat 
or Spring-based containers</li><li>JBI integration: deploy as a service engine 
in a JBI container such as ServiceMix, OpenESB or Petals</li><li>Java EE 
integration: deploy services in Java EE application servers such as Apache 
Geronimo, JOnAS, Redhat JBoss, OC4J, Oracle WebLogic, and IBM 
WebSphere</li><li>Standalone Java client/server</li></ul><h3 
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple 
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server 
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way 
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS 
for RESTful clients</li><li>Support for wrapped and non-wrapped 
styles</li><li>XML messaging API</li><li>Support for JavaScript and ECMAScript 
4 XML (E4X) - both client and server</li><li>Support for
  CORBA</li><li>Support for JBI with ServiceMix</li></ul><h3 
id="Index-Tooling">Tooling</h3><ul><li>Generating Code: WSDL to Java, WSDL to 
JavaScript, Java to JavaScript</li><li>Generating WSDL: Java to WSDL, XSD to 
WSDL, IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: WSDL to SOAP, WSDL to 
CORBA, WSDL to service</li><li>Generating Support Files: WSDL to 
IDL</li><li>Validating Files: WSDL Validation</li></ul><h2 
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently 
under heavy development. To get involved you can <a shape="rect" 
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab 
the code from the <a shape="rect" href="source-repository.html">Source 
Repository</a>. You also need to read about <a shape="rect" 
href="building.html">Building</a> CXF. For Eclipse users, you should read about 
<a shape="rect" href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
            </div>
            <!-- Content -->
          </td>

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-50645.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-50645.txt 
Thu Jun 11 16:43:09 2026        (r1093252)
@@ -0,0 +1,17 @@
+CVE-2026-50645: Apache CXF: No restriction on attachment headers per message 
+
+Severity: low 
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-core) 4.2.0 before 4.2.2
+- Apache CXF (org.apache.cxf:cxf-core) before 4.1.7
+
+Description:
+
+There is no restriction on the amount of attachment headers that a message can 
contain when being deserialized by Apache CXF, which can lead to uncontrolled 
resource consumption or a denial of service attack. Users are recommended to 
upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum 
default of 500 attachments per message.
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-50645

Modified: websites/production/cxf/content/security-advisories.html
==============================================================================
--- websites/production/cxf/content/security-advisories.html    Thu Jun 11 
16:11:01 2026        (r1093251)
+++ websites/production/cxf/content/security-advisories.html    Thu Jun 11 
16:43:09 2026        (r1093252)
@@ -99,7 +99,7 @@ Apache CXF -- Security Advisories
          <td height="100%">
            <!-- Content -->
            <div class="wiki-content">
-<div id="ConfluenceContent"><p><span style="color: rgb(36,41,47);">For 
information on how to report a new security problem please 
see<span>&#160;</span></span><a shape="rect" class="external-link" 
href="https://www.apache.org/security/"; style="text-decoration: 
none;">here</a><span style="color: 
rgb(36,41,47);">.<span>&#160;</span></span></p><h3 
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44417.txt?version=1&amp;modificationDate=1779445819000&amp;api=v2"
 data-linked-resource-id="429064531" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-44417</a>: Apache 
CXF:Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to 
RCE)</li><li><a shape="rect" href="security-advi
 
sories.data/CVE-2026-44618.txt?version=1&amp;modificationDate=1779445877000&amp;api=v2"
 data-linked-resource-id="429064532" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-44618</a>: Apache CXF: XXE 
vulnerability in WS-Transfer functionality</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44930.txt?version=1&amp;modificationDate=1779445722000&amp;api=v2"
 data-linked-resource-id="429064529" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-44930</a>: Apache CXF: 
LDAP Injectio
 n vulnerability in XKMS LDAP Repository</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-49875.txt?version=1&amp;modificationDate=1781192084000&amp;api=v2"
 data-linked-resource-id="430408836" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-49875</a>: Apache CXF: XML 
External Entity (XXE) Injection in W3CMultiSchemaFactory and 
EndpointReferenceUtils&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50623.txt?version=1&amp;modificationDate=1781192231000&amp;api=v2"
 data-linked-resource-id="430408838" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" data
 -linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50623</a>: Apache CXF: 
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50627.txt?version=1&amp;modificationDate=1781192281000&amp;api=v2"
 data-linked-resource-id="430408839" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50627</a>: Apache CXF: 
OAuth2: Missing JWT Audience and Issuer Validation in Access Token 
Validator</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50628.txt?version=1&amp;modificationDate=1781192316000&amp;api=v2"
 data-linked-resource-id="430408840" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-reso
 urce-default-alias="CVE-2026-50628.txt" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50628</a>: Apache CXF: 
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50629.txt?version=1&amp;modificationDate=1781192369000&amp;api=v2"
 data-linked-resource-id="430408842" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50629</a>: Apache CXF: 
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50630.txt?version=1&amp;modificationDate=1781192413000&amp;api=v2"
 data-linked-resource-id="4
 30408843" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50630</a>: Apache CXF: 
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm 
Injection&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50631.txt?version=1&amp;modificationDate=1781192445000&amp;api=v2"
 data-linked-resource-id="430408844" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50631</a>: Apache CXF: 
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a 
shape="rect" href="security-ad
 
visories.data/CVE-2026-50631.txt?version=1&amp;modificationDate=1781192445000&amp;api=v2"
 data-linked-resource-id="430408844" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2026-50632</a>: Apache CXF: 
JNDI Injection Vulnerability in JMSConfigFactory</li></ul><h3 
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2025-23184.txt?version=2&amp;modificationDate=1737381863000&amp;api=v2"
 data-linked-resource-id="340036025" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-linked-resource-container-ver
 sion="58">CVE-2025-23184</a>: Apache CXF: Denial of Service vulnerability with 
temporary files&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2025-48795.txt?version=1&amp;modificationDate=1752578416000&amp;api=v2"
 data-linked-resource-id="373886120" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-48795.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2025-48795</a>: Apache CXF: 
Denial of Service and sensitive data exposure in logs&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48913.txt?version=1&amp;modificationDate=1754576095000&amp;api=v2"
 data-linked-resource-id="373887565" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text 
File" data-linked-resource-con
 tent-type="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2025-48913</a>: Apache CXF: 
Untrusted JMS configuration can lead to RCE&#160;</li></ul><h3 
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2024-28752.txt?version=2&amp;modificationDate=1710431346000&amp;api=v2"
 data-linked-resource-id="296290905" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2024-28752</a>: Apache CXF SSRF 
Vulnerability using the Aegis databinding&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-29736.txt?version=1&amp;modificationDate=1721314668000&amp;api=v2"
 data-linked-resource-id="315493016" data-linked-resource-version="1" data-linke
 d-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2024-29736</a>: SSRF 
vulnerability via WADL stylesheet parameter</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-32007.txt?version=1&amp;modificationDate=1721314761000&amp;api=v2"
 data-linked-resource-id="315493017" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2024-32007</a>: Apache CXF 
Denial of Service vulnerability in JOSE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-41172.txt?version=1&amp;modificationDate=1721314821000&amp;api=v2"
 data-linked-resource
 -id="315493018" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2024-41172</a>: Unrestricted 
memory consumption in CXF HTTP clients</li></ul><h3 
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46363.txt?version=1&amp;modificationDate=1670942001000&amp;api=v2"
 data-linked-resource-id="235836918" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2022-46363</a>: Apache CXF 
directory listing / code exfiltration</li><li><a shape="rect" href="security-a
 
dvisories.data/CVE-2022-46364.txt?version=1&amp;modificationDate=1670944473000&amp;api=v2"
 data-linked-resource-id="235836926" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2022-46364</a>: Apache CXF SSRF 
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&amp;modificationDate=1623835370000&amp;api=v2"
 data-linked-resource-id="181310680" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2021-30468.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2021-304
 68</a>: Apache CXF Denial of service vulnerability in parsing JSON via 
JsonMapObjectReaderWriter</li><li><a shape="rect" 
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&amp;modificationDate=1617355743000&amp;api=v2"
 data-linked-resource-id="177049091" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2021-22696.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2021-22696</a>: OAuth 2 
authorization service vulnerable to DDos attacks</li></ul><h3 
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&amp;modificationDate=1605183671000&amp;api=v2"
 data-linked-resource-id="165225095" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-13954.txt.asc" dat
 a-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2020-13954</a>: Apache CXF 
Reflected XSS in the services listing page via the styleSheetPath</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2020-1954.txt.asc?version=1&amp;modificationDate=1585730169000&amp;api=v2"
 data-linked-resource-id="148645097" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2020-1954</a>: Apache CXF JMX 
Integration is vulnerable to a MITM attack</li></ul><h3 
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&amp;modificationDate=1584610519000&amp;api=v2"
 data-linked-r
 esource-id="145722246" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-17573.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2019-17573</a>: Apache CXF 
Reflected XSS in the services listing page</li><li><a shape="rect" 
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&amp;modificationDate=1579178393000&amp;api=v2"
 data-linked-resource-id="145722244" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12423.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2019-12423</a>: Apache CXF 
OpenId Connect JWK Keys service returns private/secret credentials if 
configured with a jwk keystore</li><li
 ><a shape="rect" 
 >href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&amp;modificationDate=1572961201000&amp;api=v2"
 > data-linked-resource-id="135859612" data-linked-resource-version="2" 
 >data-linked-resource-type="attachment" 
 >data-linked-resource-default-alias="CVE-2019-12419.txt.asc" 
 >data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
 >data-linked-resource-container-id="27837502" 
 >data-linked-resource-container-version="58">CVE-2019-12419</a>: Apache CXF 
 >OpenId Connect token service does not properly validate the 
 >clientId</li><li><a shape="rect" 
 >href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&amp;modificationDate=1572957147000&amp;api=v2"
 > data-linked-resource-id="135859607" data-linked-resource-version="1" 
 >data-linked-resource-type="attachment" 
 >data-linked-resource-default-alias="CVE-2019-12406.txt.asc" 
 >data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
 >data-linked-resource-container-id="27837502" data-linked-reso
 urce-container-version="58">CVE-2019-12406</a>: Apache CXF does not restrict 
the number of message attachments</li></ul><h3 
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&amp;modificationDate=1530184663000&amp;api=v2"
 data-linked-resource-id="87296645" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2018-8039</a>: Apache CXF TLS 
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&amp;modificationDate=1530712328000&amp;api=v2"
 data-linked-resource-id="87297524" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-resource-default-
 alias="CVE-2018-8038.txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2018-8038</a>: Apache CXF Fediz 
is vulnerable to DTD based XML attacks</li></ul><h3 
id="SecurityAdvisories-2017">2017</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&amp;modificationDate=1512037276000&amp;api=v2"
 data-linked-resource-id="74688816" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12631.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2017-12631</a>: CSRF 
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&amp;modificationDate=1510661632000&amp;api=v
 2" data-linked-resource-id="74687100" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12624.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2017-12624</a>: Apache CXF web 
services that process attachments are vulnerable to Denial of Service (DoS) 
attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&amp;modificationDate=1494949377000&amp;api=v2"
 data-linked-resource-id="70255583" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2017-7662</a>: The Apache CXF 
Fediz OIDC Client Registration Service is vulne
 rable to CSRF attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&amp;modificationDate=1494949364000&amp;api=v2"
 data-linked-resource-id="70255582" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7661.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2017-7661</a>: The Apache CXF 
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&amp;modificationDate=1492515113000&amp;api=v2"
 data-linked-resource-id="69406543" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837
 502" data-linked-resource-container-version="58">CVE-2017-5656</a>: Apache 
CXF's STSClient uses a flawed way of caching tokens that are associated with 
delegation tokens.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&amp;modificationDate=1492515074000&amp;api=v2"
 data-linked-resource-id="69406542" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2017-5653</a>: Apache CXF 
JAX-RS XML Security streaming clients do not validate that the service response 
was signed or encrypted.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&amp;modificationDate=1487590374000&amp;api=v2"
 data-linked-resource-id="68715428" data-linked-resource-version="1" 
data-linked-resource-type=
 "attachment" data-linked-resource-default-alias="CVE-2017-3156.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2017-3156</a>: Apache CXF 
OAuth2 Hawk and JOSE MAC Validation code is vulnerable to the timing 
attacks</li></ul><h3 id="SecurityAdvisories-2016">2016</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635454" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2016-8739</a>: Atom entity 
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect" 
href="security-advisories.data/CVE-
 2016-6812.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2" 
data-linked-resource-id="67635455" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2016-6812</a>: XSS risk in 
Apache CXF FormattedServiceListWriter when a request URL contains matrix 
parameters</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&amp;modificationDate=1473350153000&amp;api=v2"
 data-linked-resource-id="65869472" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2016-4464</
 a>: Apache CXF Fediz application plugins do not match the SAML 
AudienceRestriction values against the list of configured audience 
URIs</li></ul><h3 id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&amp;modificationDate=1447433340000&amp;api=v2"
 data-linked-resource-id="61328642" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2015-5253</a>: Apache CXF SAML 
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&amp;modificationDate=1440598018000&amp;api=v2"
 data-linked-resource-id="61316328" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-resource-d
 efault-alias="CVE-2015-5175.txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2015-5175</a>: Apache CXF Fediz 
application plugins are vulnerable to Denial of Service (DoS) 
attacks</li></ul><h3 id="SecurityAdvisories-2014">2014</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&amp;modificationDate=1419245371000&amp;api=v2"
 data-linked-resource-id="51183657" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-3577</a>: Apache CXF SSL 
hostname verification bypass</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&amp;modificationDate=141874
 0474000&amp;api=v2" data-linked-resource-id="50561078" 
data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">Note on CVE-2014-3566</a>: SSL 3.0 
support in Apache CXF, aka the "POODLE" attack.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&amp;modificationDate=1414169368000&amp;api=v2"
 data-linked-resource-id="47743195" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-3623</a>: Apache CXF does 
not properly enforce the security semantics of SAML SubjectConfirma
 tion methods when used with the TransportBinding</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&amp;modificationDate=1414169326000&amp;api=v2"
 data-linked-resource-id="47743194" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3584.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-3584</a>: Apache CXF 
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS) 
attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&amp;modificationDate=1398873370000&amp;api=v2"
 data-linked-resource-id="40895138" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" data-linke
 d-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-0109</a>: HTML content 
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&amp;modificationDate=1398873378000&amp;api=v2"
 data-linked-resource-id="40895139" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-0110</a>: Large invalid 
content could cause temporary space to fill</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&amp;modificationDate=1398873385000&amp;api=v2"
 data-linked-resource-id="40895140" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0034.txt.asc"
  data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-0034</a>: The 
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2014-0035.txt.asc?version=1&amp;modificationDate=1398873391000&amp;api=v2"
 data-linked-resource-id="40895141" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2014-0035</a>: UsernameTokens 
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3 
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&amp;modificationDate=1372324301000&amp;api
 =v2" data-linked-resource-id="33095710" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="58">CVE-2013-2160</a> - Denial of 
Service Attacks on Apache CXF</li><li><a shape="rect" 
href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML Encryption backwards 
compatibility attack on Apache CXF.</li><li><a shape="rect" 
href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication bypass in the case 
of WS-SecurityPolicy enabled plaintext UsernameTokens.</li></ul><h3 
id="SecurityAdvisories-2012">2012</h3><ul><li><a shape="rect" 
href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor always allows 
HTTP Get requests from browser.</li><li><a shape="rect" 
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher 
attack against dis
 tributed symmetric key in WS-Security.</li><li><a shape="rect" 
href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is vulnerable to SOAP 
Action spoofing attacks on Document Literal web services.</li><li><a 
shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> - Apache CXF does not 
verify that elements were signed or encrypted by a particular Supporting 
Token.</li><li><a shape="rect" href="cve-2012-2378.html">CVE-2012-2378</a> - 
Apache CXF does not pick up some child policies of WS-SecurityPolicy 1.1 
SupportingToken policy assertions on the client side.</li><li><a shape="rect" 
href="note-on-cve-2011-1096.html">Note on CVE-2011-1096</a> - XML Encryption 
flaw / Character pattern encoding attack.</li><li><a shape="rect" 
href="cve-2012-0803.html">CVE-2012-0803</a> - Apache CXF does not validate 
UsernameToken policies correctly.</li></ul><h3 
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect" 
class="external-link" href="http://svn.apache.org/repos/asf/cxf/trunk/security/
 CVE-2010-2076.pdf">CVE-2010-2076</a> - DTD based XML attacks.</li></ul><p><br 
clear="none"></p></div>
+<div id="ConfluenceContent"><p><span style="color: rgb(36,41,47);">For 
information on how to report a new security problem please 
see<span>&#160;</span></span><a shape="rect" class="external-link" 
href="https://www.apache.org/security/"; style="text-decoration: 
none;">here</a><span style="color: 
rgb(36,41,47);">.<span>&#160;</span></span></p><h3 
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44417.txt?version=1&amp;modificationDate=1779445819000&amp;api=v2"
 data-linked-resource-id="429064531" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-44417</a>: Apache 
CXF:Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to 
RCE)</li><li><a shape="rect" href="security-advi
 
sories.data/CVE-2026-44618.txt?version=1&amp;modificationDate=1779445877000&amp;api=v2"
 data-linked-resource-id="429064532" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-44618</a>: Apache CXF: XXE 
vulnerability in WS-Transfer functionality</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44930.txt?version=1&amp;modificationDate=1779445722000&amp;api=v2"
 data-linked-resource-id="429064529" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-44930</a>: Apache CXF: 
LDAP Injectio
 n vulnerability in XKMS LDAP Repository</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-49875.txt?version=1&amp;modificationDate=1781192084000&amp;api=v2"
 data-linked-resource-id="430408836" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-49875</a>: Apache CXF: XML 
External Entity (XXE) Injection in W3CMultiSchemaFactory and 
EndpointReferenceUtils&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50623.txt?version=1&amp;modificationDate=1781192231000&amp;api=v2"
 data-linked-resource-id="430408838" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" data
 -linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50623</a>: Apache CXF: 
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50627.txt?version=1&amp;modificationDate=1781192281000&amp;api=v2"
 data-linked-resource-id="430408839" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50627</a>: Apache CXF: 
OAuth2: Missing JWT Audience and Issuer Validation in Access Token 
Validator</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50628.txt?version=1&amp;modificationDate=1781192316000&amp;api=v2"
 data-linked-resource-id="430408840" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-reso
 urce-default-alias="CVE-2026-50628.txt" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50628</a>: Apache CXF: 
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50629.txt?version=1&amp;modificationDate=1781192369000&amp;api=v2"
 data-linked-resource-id="430408842" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50629</a>: Apache CXF: 
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50630.txt?version=1&amp;modificationDate=1781192413000&amp;api=v2"
 data-linked-resource-id="4
 30408843" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50630</a>: Apache CXF: 
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm 
Injection&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50631.txt?version=1&amp;modificationDate=1781192445000&amp;api=v2"
 data-linked-resource-id="430408844" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50631</a>: Apache CXF: 
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a 
shape="rect" href="security-ad
 
visories.data/CVE-2026-50631.txt?version=1&amp;modificationDate=1781192445000&amp;api=v2"
 data-linked-resource-id="430408844" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50632</a>: Apache CXF: 
JNDI Injection Vulnerability in JMSConfigFactory</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50633.txt?version=1&amp;modificationDate=1781192513000&amp;api=v2"
 data-linked-resource-id="430408847" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50633</a>: Apache CXF: 
JNDI Inje
 ction vulnerability in DispatchMDBMessageListenerImpl</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50633.txt?version=1&amp;modificationDate=1781192513000&amp;api=v2"
 data-linked-resource-id="430408847" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50634</a>: Apache CXF: WS 
JSON request filter trusts metadata from an unvalidated first signature 
entry</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50634.txt?version=1&amp;modificationDate=1781192545000&amp;api=v2"
 data-linked-resource-id="430408848" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50634.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" dat
 a-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2026-50645</a>: Apache CXF: No 
restriction on attachment headers per message</li></ul><h3 
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2025-23184.txt?version=2&amp;modificationDate=1737381863000&amp;api=v2"
 data-linked-resource-id="340036025" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2025-23184</a>: Apache CXF: 
Denial of Service vulnerability with temporary files&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48795.txt?version=1&amp;modificationDate=1752578416000&amp;api=v2"
 data-linked-resource-id="373886120" data-linked-resource-version="1" 
data-linked-resource-type="att
 achment" data-linked-resource-default-alias="CVE-2025-48795.txt" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2025-48795</a>: Apache CXF: 
Denial of Service and sensitive data exposure in logs&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48913.txt?version=1&amp;modificationDate=1754576095000&amp;api=v2"
 data-linked-resource-id="373887565" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2025-48913</a>: Apache CXF: 
Untrusted JMS configuration can lead to RCE&#160;</li></ul><h3 
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2024-28752.txt?version=2&am
 p;modificationDate=1710431346000&amp;api=v2" 
data-linked-resource-id="296290905" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2024-28752</a>: Apache CXF SSRF 
Vulnerability using the Aegis databinding&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-29736.txt?version=1&amp;modificationDate=1721314668000&amp;api=v2"
 data-linked-resource-id="315493016" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2024-29736</a>: SSRF 
vulnerability via WADL stylesheet parameter</li><li><a sha
 pe="rect" 
href="security-advisories.data/CVE-2024-32007.txt?version=1&amp;modificationDate=1721314761000&amp;api=v2"
 data-linked-resource-id="315493017" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2024-32007</a>: Apache CXF 
Denial of Service vulnerability in JOSE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-41172.txt?version=1&amp;modificationDate=1721314821000&amp;api=v2"
 data-linked-resource-id="315493018" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2024-41172</a>: Unre
 stricted memory consumption in CXF HTTP clients</li></ul><h3 
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46363.txt?version=1&amp;modificationDate=1670942001000&amp;api=v2"
 data-linked-resource-id="235836918" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2022-46363</a>: Apache CXF 
directory listing / code exfiltration</li><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46364.txt?version=1&amp;modificationDate=1670944473000&amp;api=v2"
 data-linked-resource-id="235836926" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" da
 ta-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2022-46364</a>: Apache CXF SSRF 
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&amp;modificationDate=1623835370000&amp;api=v2"
 data-linked-resource-id="181310680" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2021-30468.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2021-30468</a>: Apache CXF 
Denial of service vulnerability in parsing JSON via 
JsonMapObjectReaderWriter</li><li><a shape="rect" 
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&amp;modificationDate=1617355743000&amp;api=v2"
 data-linked-resource-id="177049091" data-linked-resource-version="1" 
data-linked-resource-type="att
 achment" data-linked-resource-default-alias="CVE-2021-22696.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2021-22696</a>: OAuth 2 
authorization service vulnerable to DDos attacks</li></ul><h3 
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&amp;modificationDate=1605183671000&amp;api=v2"
 data-linked-resource-id="165225095" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-13954.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2020-13954</a>: Apache CXF 
Reflected XSS in the services listing page via the styleSheetPath</li><li><a 
shape="rect" href="security-advisories.data/CVE-2020-1954.txt.a
 sc?version=1&amp;modificationDate=1585730169000&amp;api=v2" 
data-linked-resource-id="148645097" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2020-1954</a>: Apache CXF JMX 
Integration is vulnerable to a MITM attack</li></ul><h3 
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&amp;modificationDate=1584610519000&amp;api=v2"
 data-linked-resource-id="145722246" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-17573.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2019-1757
 3</a>: Apache CXF Reflected XSS in the services listing page</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&amp;modificationDate=1579178393000&amp;api=v2"
 data-linked-resource-id="145722244" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12423.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2019-12423</a>: Apache CXF 
OpenId Connect JWK Keys service returns private/secret credentials if 
configured with a jwk keystore</li><li><a shape="rect" 
href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&amp;modificationDate=1572961201000&amp;api=v2"
 data-linked-resource-id="135859612" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12419.txt.asc" 
data-nice-type="Text File" data-lin
 ked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2019-12419</a>: Apache CXF 
OpenId Connect token service does not properly validate the clientId</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&amp;modificationDate=1572957147000&amp;api=v2"
 data-linked-resource-id="135859607" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12406.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2019-12406</a>: Apache CXF does 
not restrict the number of message attachments</li></ul><h3 
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&amp;modificationDate=1530184663000&amp;api=v2"
 data-linked-resource-id="87296645" 
 data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2018-8039</a>: Apache CXF TLS 
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&amp;modificationDate=1530712328000&amp;api=v2"
 data-linked-resource-id="87297524" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8038.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2018-8038</a>: Apache CXF Fediz 
is vulnerable to DTD based XML attacks</li></ul><h3 
id="SecurityAdvisories-2017">2017</h3><ul><li><a s
 hape="rect" 
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&amp;modificationDate=1512037276000&amp;api=v2"
 data-linked-resource-id="74688816" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12631.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2017-12631</a>: CSRF 
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&amp;modificationDate=1510661632000&amp;api=v2"
 data-linked-resource-id="74687100" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12624.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60
 ">CVE-2017-12624</a>: Apache CXF web services that process attachments are 
vulnerable to Denial of Service (DoS) attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&amp;modificationDate=1494949377000&amp;api=v2"
 data-linked-resource-id="70255583" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2017-7662</a>: The Apache CXF 
Fediz OIDC Client Registration Service is vulnerable to CSRF 
attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&amp;modificationDate=1494949364000&amp;api=v2"
 data-linked-resource-id="70255582" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7661.txt.asc" data-nic
 e-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2017-7661</a>: The Apache CXF 
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&amp;modificationDate=1492515113000&amp;api=v2"
 data-linked-resource-id="69406543" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2017-5656</a>: Apache CXF's 
STSClient uses a flawed way of caching tokens that are associated with 
delegation tokens.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&amp;modificationDate=1492515074000&amp;api=v2"
 data-linked-resource-id="6
 9406542" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2017-5653</a>: Apache CXF 
JAX-RS XML Security streaming clients do not validate that the service response 
was signed or encrypted.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&amp;modificationDate=1487590374000&amp;api=v2"
 data-linked-resource-id="68715428" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-3156.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2017-3156</a>: Apache CXF 
OAuth2 Hawk and JOSE MAC Validation code is vulnerable to the timi
 ng attacks</li></ul><h3 id="SecurityAdvisories-2016">2016</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635454" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2016-8739</a>: Atom entity 
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-6812.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635455" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" data-linked-reso
 urce-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2016-6812</a>: XSS risk in 
Apache CXF FormattedServiceListWriter when a request URL contains matrix 
parameters</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&amp;modificationDate=1473350153000&amp;api=v2"
 data-linked-resource-id="65869472" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2016-4464</a>: Apache CXF Fediz 
application plugins do not match the SAML AudienceRestriction values against 
the list of configured audience URIs</li></ul><h3 
id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&amp;modificationDate=1447433340000&amp;api=v2"
 data-linked
 -resource-id="61328642" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2015-5253</a>: Apache CXF SAML 
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&amp;modificationDate=1440598018000&amp;api=v2"
 data-linked-resource-id="61316328" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5175.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2015-5175</a>: Apache CXF Fediz 
application plugins are vulnerable to Denial of Service (DoS) 
attacks</li></ul><h3 id="Security
 Advisories-2014">2014</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&amp;modificationDate=1419245371000&amp;api=v2"
 data-linked-resource-id="51183657" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-3577</a>: Apache CXF SSL 
hostname verification bypass</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&amp;modificationDate=1418740474000&amp;api=v2"
 data-linked-resource-id="50561078" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-linked-resource-conta
 iner-version="60">Note on CVE-2014-3566</a>: SSL 3.0 support in Apache CXF, 
aka the "POODLE" attack.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&amp;modificationDate=1414169368000&amp;api=v2"
 data-linked-resource-id="47743195" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-3623</a>: Apache CXF does 
not properly enforce the security semantics of SAML SubjectConfirmation methods 
when used with the TransportBinding</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&amp;modificationDate=1414169326000&amp;api=v2"
 data-linked-resource-id="47743194" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-resource-default-alias="CVE-2
 014-3584.txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-3584</a>: Apache CXF 
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS) 
attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&amp;modificationDate=1398873370000&amp;api=v2"
 data-linked-resource-id="40895138" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-0109</a>: HTML content 
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&amp;modificationDate=1398873378000&amp;api=v2"
 data-linked-resource-id="40895139" data
 -linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-0110</a>: Large invalid 
content could cause temporary space to fill</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&amp;modificationDate=1398873385000&amp;api=v2"
 data-linked-resource-id="40895140" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0034.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-0034</a>: The 
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a 
shape="rect" href="security-advisories.data/CVE-2014-0035.txt.asc?v
 ersion=1&amp;modificationDate=1398873391000&amp;api=v2" 
data-linked-resource-id="40895141" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="60">CVE-2014-0035</a>: UsernameTokens 
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3 
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&amp;modificationDate=1372324301000&amp;api=v2"
 data-linked-resource-id="33095710" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="6
 0">CVE-2013-2160</a> - Denial of Service Attacks on Apache CXF</li><li><a 
shape="rect" href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML 
Encryption backwards compatibility attack on Apache CXF.</li><li><a 
shape="rect" href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication 
bypass in the case of WS-SecurityPolicy enabled plaintext 
UsernameTokens.</li></ul><h3 id="SecurityAdvisories-2012">2012</h3><ul><li><a 
shape="rect" href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor 
always allows HTTP Get requests from browser.</li><li><a shape="rect" 
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher 
attack against distributed symmetric key in WS-Security.</li><li><a 
shape="rect" href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is 
vulnerable to SOAP Action spoofing attacks on Document Literal web 
services.</li><li><a shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> - 
Apache CXF does not verify that elements were signed or encry
 pted by a particular Supporting Token.</li><li><a shape="rect" 
href="cve-2012-2378.html">CVE-2012-2378</a> - Apache CXF does not pick up some 
child policies of WS-SecurityPolicy 1.1 SupportingToken policy assertions on 
the client side.</li><li><a shape="rect" href="note-on-cve-2011-1096.html">Note 
on CVE-2011-1096</a> - XML Encryption flaw / Character pattern encoding 
attack.</li><li><a shape="rect" href="cve-2012-0803.html">CVE-2012-0803</a> - 
Apache CXF does not validate UsernameToken policies correctly.</li></ul><h3 
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf";>CVE-2010-2076</a>
 - DTD based XML attacks.</li></ul><p><br clear="none"></p></div>
            </div>
            <!-- Content -->
          </td>


Reply via email to