Author: buildbot
Date: Thu Aug 6 11:43:11 2026
New Revision: 1093641
Log:
Production update by buildbot for cxf
Added:
websites/production/cxf/content/security-advisories.data/CVE-2026-65583.txt
websites/production/cxf/content/security-advisories.data/CVE-2026-68079.txt
websites/production/cxf/content/security-advisories.data/CVE-2026-68481.txt
Modified:
websites/production/cxf/content/cache/main.pageCache
websites/production/cxf/content/index.html
websites/production/cxf/content/security-advisories.html
Modified: websites/production/cxf/content/cache/main.pageCache
==============================================================================
Binary file (source and/or target). No diff available.
Modified: websites/production/cxf/content/index.html
==============================================================================
--- websites/production/cxf/content/index.html Thu Aug 6 10:43:11 2026
(r1093640)
+++ websites/production/cxf/content/index.html Thu Aug 6 11:43:11 2026
(r1093641)
@@ -99,7 +99,7 @@ Apache CXF -- Index
<td height="100%">
<!-- Content -->
<div class="wiki-content">
-<div id="ConfluenceContent"><h1
id="Index-ApacheCXF™:AnOpen-SourceServicesFramework">Apache CXF™:
An Open-Source Services Framework</h1><h2
id="Index-Overview">Overview</h2><p>Apache CXF™ is an open source
services framework. CXF helps you build and develop services using frontend
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a
variety of transports such as HTTP, JMS or JBI.</p><h2
id="Index-News">News</h2><h3
id="Index-Augest5,2026-ApacheCXF4.2.3,4.1.8and3.6.12released!">Augest 5, 2026 -
Apache CXF 4.2.3, 4.1.8 and 3.6.12 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 10 JIRA issues were fixed for 4.2.3, 6 JIRA issues
were fixed for 4.1.8. and  4 JIRA issues were fixed for
3.6.12.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3 id="Index-June
10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache CXF 4.2.2 and
4.1.7 released!</h3><p>The Apache CXF team is proud to announce the
availability of our latest patch releases! </p><p>Over 5 JIRA issues were
fixed for 4.2.2 and  4 JIRA issues were fixed for 4.1.7.</p><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><p>These
releases contain fixes for multiple CVE issues, please see <a shape="rect"
href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2026 -
Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 15 JIRA issues were fixed for 4.2.1,  10 JIRA
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for
3.6.11.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases contain fixes for 3
CVE issues, please see <a shape="rect"
href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16,
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache
CXF team is proud to announce the availability of our latest patch
releases! </p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues
were fixed for 4.1.5,  14 JIRA issues were fixed for 4.0.11, 8 JIRA issues
were fixed for 3.6.10.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 2025 -
Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 13 JIRA issues were fixed for 4.1.4,  11 JIRA
issues were fixed for 4.0.10, 12 JIRA issues were fixed for
3.6.9.</p><p>Downloads are available <a shape="re
ct" href="download.html">here</a>.</p><h3
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 -
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 10 JIRA
issues were fixed for 4.1.3 and 4.0.9, </p><p>6 JIRA issues were fixed for
3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt">https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 -
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 16 JIRA
issues were fixed for 4.1.2, </p><p>11 JIRA issues were fixed for 4.0.8,
10 JIRA issue
s were fixed for 3.6.7.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 -
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team
is proud to announce the availability of our latest patch releases!  Over
17 JIRA issues were fixed for 4.1.1, </p><p>14 JIRA issues were fixed for
4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA issues were fixed for
3.5.11.</p><p>Please note that the CXF 3.5.11 is the last release of CXF 3.5.x
series</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0
released!</h3><p>The Apache CXF team is proud to announce the availability of
CXF 4.1.0!  The 4.1.0 is our first release to feature Jakarta EE 10
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for
4.1.0, </p><p
>Downloads are available <a shape="rect"
>href="download.html">here</a>.</p><h3
>id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 -
>Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is
>proud to announce the availability of our latest patch releases!  Over
>29 JIRA issues were fixed for 4.0.6, </p><p>25 JIRA issues were fixed
>for 3.6.5 and 18 JIRA issues were fixed for 3.5.10.</p><p>Downloads are
>available <a shape="rect" href="download.html">here</a>.</p><h3
>id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July 17, 2024 -
>Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF team is
>proud to announce the availability of our latest patch releases!  Over
>19 JIRA issues were fixed for 4.0.5.</p><p>These releases contain fixes for 3
>different CVEs:</p><ul><li><a shape="rect"
>href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt">https://cxf.apache.org/security-advisories.data/CV
E-2024-29736.txt</a></li><li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 12, 2024 -
Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 28 JIRA
issues were fixed for 4.0.4.</p><p>These releases contain a fix for a new
security issue: <a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
are available <a shape="rect" href
="download.html">here</a>.</p><h3
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 -
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2released!">June 12, 2023 - Apache
CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache CXF team is proud to announce
the availability of our latest patch releases!  Over 7 JIRA issues were
fixed for 4.0.2 and 3.6.1.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to
announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for
4.01 and 3.5.6.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3 id="Index-Features">Features</h3><p>CXF
includes a broad feature set, but it is primarily focused on the following
areas:</p><ul><li><strong>Web Services Standards Support:</strong> CXF supports
a variety of web service standards including SOAP, the WS-I Basic Profile,
WSDL, WS-Addressing, WS-Policy, WS-ReliableMessaging, WS-Security,
WS-SecurityPolicy, WS-SecureConverstation, and WS-Trust
(partial).</li><li><strong>Frontends:</strong> CXF supports a variety of
"frontend" programming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF
JAX-WS support includes some extensions to the standard that make it
significantly easier to use, compared to the reference implementation: It will
automatically generate code for request and response bean classes, and does not
require a WSDL for simple cases.</p><p>It also includes a "simple frontend"
which allows creation of clients and endpo
ints without annotations. CXF supports both contract first development with
WSDL and code first development starting from Java.</p><p>For REST, CXF also
supports a JAX-RS frontend.</p><ul><li><strong>Ease of use:</strong> CXF is
designed to be intuitive and easy to use. There are simple APIs to quickly
build code-first services, Maven plug-ins to make tooling integration easy,
JAX-WS API support, Spring 2.x XML support to make configuration a snap, and
much more.</li><li><strong>Binary and Legacy Protocol Support:</strong> CXF has
been designed to provide a pluggable architecture that supports not only XML
but also non-XML type bindings, such as JSON and CORBA, in combination with any
type of transport.</li></ul><p>To get started using CXF, check out the <a
shape="rect" href="download.html">downloads</a>, the <a shape="rect"
href="http://cxf.apache.org/docs/index.html">user's guide</a>, or the <a
shape="rect" href="mailing-lists.html">mailing lists</a> to get more
information!</p><h
2 id="Index-Goals">Goals</h2><h3 id="Index-General">General</h3><ul><li>High
Performance</li><li>Extensible</li><li>Intuitive & Easy to Use</li></ul><h3
id="Index-SupportforStandards">Support for Standards</h3><h5
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=224"
rel="nofollow">JSR-224</a></li><li>Web Services Metadata for the Java Platform
- <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=181"
rel="nofollow">JSR-181</a></li><li>JAX-RS - The Java API for RESTful Web
Services - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=311" rel="nofollow">JSR-311,</a> <a
shape="rect" class="external-link" href="https://jcp.org/en/jsr/detail?id=370"
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java
(SAAJ) - <a shape="rect" class="external-link" href="http://jcp.org/aboutJava/
communityprocess/mrel/jsr067/index3.html"
rel="nofollow">JSR-67</a></li></ul><h5
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web
Service Definition Language</li><li>Communication Security: WS-Security,
WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial
support)</li><li>Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message
Transmission Optimization Mechanism (MTOM)</li></ul><h5
id="Index-OpenAPISpecification(OAS)Support">OpenAPI Specification (OAS)
Support</h5><ul><li>OAS 2.0 (classic Swagger specification)</li><li>OAS 3.0.x
(new revised specification)</li></ul><h3
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple
Transports, Protocol Bindings, Data Bindings, and
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via
the <a shape="rect
" class="external-link"
href="http://camel.apache.org/camel-transport-for-cxf.html">Camel transport for
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP,
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans,
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON,
FastInfoset</li><li>Extensibility API allows additional bindings for CXF,
enabling additional message format support such as CORBA/IIOP</li></ul><h3
id="Index-FlexibleDeployment">Flexible Deployment</h3><ul><li>Lightweight
containers: deploy services in Jetty, Tomcat or Spring-based
containers</li><li>JBI integration: deploy as a service engine in a JBI
container such as ServiceMix, OpenESB or Petals</li><li>Java EE integration:
deploy services in Java EE application servers such as Apache Geronimo, JOnAS,
Redhat JBoss, OC4J, Oracle WebLogic, and IBM WebSphere</li><li>Standalone Java
client/server</li></ul><h3
id="Index-SupportforMultipleProgrammingLanguages">Supp
ort for Multiple Programming Languages</h3><ul><li>Full support for JAX-WS 2.x
client/server programming model</li><li>JAX-WS 2.x synchronous, asynchronous
and one-way API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII)
API</li><li>JAX-RS for RESTful clients</li><li>Support for wrapped and
non-wrapped styles</li><li>XML messaging API</li><li>Support for JavaScript and
ECMAScript 4 XML (E4X) - both client and server</li><li>Support for
CORBA</li><li>Support for JBI with ServiceMix</li></ul><h3
id="Index-Tooling">Tooling</h3><ul><li>Generating Code: WSDL to Java, WSDL to
JavaScript, Java to JavaScript</li><li>Generating WSDL: Java to WSDL, XSD to
WSDL, IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: WSDL to SOAP, WSDL to
CORBA, WSDL to service</li><li>Generating Support Files: WSDL to
IDL</li><li>Validating Files: WSDL Validation</li></ul><h2
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently
under heavy development. To get involved you can <a shape=
"rect" href="mailing-lists.html">subscribe to the mailing lists</a>. You can
also grab the code from the <a shape="rect"
href="source-repository.html">Source Repository</a>. You also need to read
about <a shape="rect" href="building.html">Building</a> CXF. For Eclipse users,
you should read about <a shape="rect" href="setting-up-eclipse.html">Setting up
Eclipse</a>.</p></div>
+<div id="ConfluenceContent"><h1
id="Index-ApacheCXF™:AnOpen-SourceServicesFramework">Apache CXF™:
An Open-Source Services Framework</h1><h2
id="Index-Overview">Overview</h2><p>Apache CXF™ is an open source
services framework. CXF helps you build and develop services using frontend
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a
variety of transports such as HTTP, JMS or JBI.</p><h2
id="Index-News">News</h2><h3
id="Index-August5,2026-ApacheCXF4.2.3,4.1.8and3.6.12released!">August 5, 2026 -
Apache CXF 4.2.3, 4.1.8 and 3.6.12 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 10 JIRA issues were fixed for 4.2.3, 6 JIRA issues
were fixed for 4.1.8. and  4 JIRA issues were fixed for
3.6.12.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases
contain fixes for multiple CVE issues, please see <a shape="rect"
href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce
the availability of our latest patch releases! </p><p>Over 5 JIRA issues
were fixed for 4.2.2 and  4 JIRA issues were fixed for
4.1.7.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases contain fixes for multiple
CVE issues, please see <a shape="rect" href="security-advisories.html">Security
Advisories</a>.</p><h3
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2026 -
Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 15 JIRA issues were fixed for 4.2.1,  10 JIRA
issues were fixed for 4.1.6, and 8 JIRA issues we
re fixed for 3.6.11.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE
issues, please see <a shape="rect"
href="security-advisories.html">Security Advisories</a>.</p><h3
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16,
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache
CXF team is proud to announce the availability of our latest patch
releases! </p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues
were fixed for 4.1.5,  14 JIRA issues were fixed for 4.0.11, 8 JIRA issues
were fixed for 3.6.10.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 2025 -
Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch
releases! </p><p>Over 13 JIRA issues were f
ixed for 4.1.4,  11 JIRA issues were fixed for 4.0.10, 12 JIRA issues
were fixed for 3.6.9.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 -
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 10 JIRA
issues were fixed for 4.1.3 and 4.0.9, </p><p>6 JIRA issues were fixed for
3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt">https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 -
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud
to announce the availabil
ity of our latest patch releases!  Over 16 JIRA issues were fixed for
4.1.2, </p><p>11 JIRA issues were fixed for 4.0.8, 10 JIRA issues were
fixed for 3.6.7.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 -
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team
is proud to announce the availability of our latest patch releases!  Over
17 JIRA issues were fixed for 4.1.1, </p><p>14 JIRA issues were fixed for
4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA issues were fixed for
3.5.11.</p><p>Please note that the CXF 3.5.11 is the last release of CXF 3.5.x
series</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0
released!</h3><p>The Apache CXF team is proud to announce the availability of
CXF 4.1.0!  
;The 4.1.0 is our first release to feature Jakarta EE 10 support and JDK-17
baseline</p><p>Over 54 JIRA issues were fixed for 4.1.0, </p><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 -
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is
proud to announce the availability of our latest patch releases!  Over 29
JIRA issues were fixed for 4.0.6, </p><p>25 JIRA issues were fixed for
3.6.5 and 18 JIRA issues were fixed for 3.5.10.</p><p>Downloads are
available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July 17, 2024 -
Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 19 JIRA
issues were fixed for 4.0.5.</p><p>These releases contain fixes for 3 different
CVEs:</p><ul>
<li><a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
shape="rect"
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 12, 2024 -
Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 28 JIRA
issues were fixed for 4.0.4.</p><p>These releases contain a fix for a new
security issue: <a shape="rect"
href="https://cxf.apache.org/security-advisories.data/CV
E-2024-28752.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
are available <a shape="rect" href="download.html">here</a>.</p><h3
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 -
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud
to announce the availability of our latest patch releases!  Over 15 JIRA
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available <a
shape="rect" href="download.html">here</a>.</p><h3
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2released!">June 12, 2023 - Apache
CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache CXF team is proud to announce
the availability of our latest patch releases!  Over 7 JIRA issues were
fixed for 4.0.2 and 3.6.1.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache
CXF 3.5.6, 3.6.0 and 4.0.1 r
eleased!</h3><p>The Apache CXF team is proud to announce the availability of
our latest patch releases!  Over 15 JIRA issues were fixed for 4.01 and
3.5.6.</p><p>Downloads are available <a shape="rect"
href="download.html">here</a>.</p><h3 id="Index-Features">Features</h3><p>CXF
includes a broad feature set, but it is primarily focused on the following
areas:</p><ul><li><strong>Web Services Standards Support:</strong> CXF supports
a variety of web service standards including SOAP, the WS-I Basic Profile,
WSDL, WS-Addressing, WS-Policy, WS-ReliableMessaging, WS-Security,
WS-SecurityPolicy, WS-SecureConverstation, and WS-Trust
(partial).</li><li><strong>Frontends:</strong> CXF supports a variety of
"frontend" programming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF
JAX-WS support includes some extensions to the standard that make it
significantly easier to use, compared to the reference implementation: It will
automatically generate code for request and response b
ean classes, and does not require a WSDL for simple cases.</p><p>It also
includes a "simple frontend" which allows creation of clients and endpoints
without annotations. CXF supports both contract first development with WSDL and
code first development starting from Java.</p><p>For REST, CXF also supports a
JAX-RS frontend.</p><ul><li><strong>Ease of use:</strong> CXF is designed to be
intuitive and easy to use. There are simple APIs to quickly build code-first
services, Maven plug-ins to make tooling integration easy, JAX-WS API support,
Spring 2.x XML support to make configuration a snap, and much
more.</li><li><strong>Binary and Legacy Protocol Support:</strong> CXF has been
designed to provide a pluggable architecture that supports not only XML but
also non-XML type bindings, such as JSON and CORBA, in combination with any
type of transport.</li></ul><p>To get started using CXF, check out the <a
shape="rect" href="download.html">downloads</a>, the <a shape="rect"
href="http://cxf
.apache.org/docs/index.html">user's guide</a>, or the <a shape="rect"
href="mailing-lists.html">mailing lists</a> to get more information!</p><h2
id="Index-Goals">Goals</h2><h3 id="Index-General">General</h3><ul><li>High
Performance</li><li>Extensible</li><li>Intuitive & Easy to Use</li></ul><h3
id="Index-SupportforStandards">Support for Standards</h3><h5
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=224"
rel="nofollow">JSR-224</a></li><li>Web Services Metadata for the Java Platform
- <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=181"
rel="nofollow">JSR-181</a></li><li>JAX-RS - The Java API for RESTful Web
Services - <a shape="rect" class="external-link"
href="http://jcp.org/en/jsr/detail?id=311" rel="nofollow">JSR-311,</a> <a
shape="rect" class="external-link" href="https://jcp.org/en/jsr/detail?id=370"
rel="nofoll
ow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java (SAAJ) - <a
shape="rect" class="external-link"
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"
rel="nofollow">JSR-67</a></li></ul><h5
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web
Service Definition Language</li><li>Communication Security: WS-Security,
WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial
support)</li><li>Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message
Transmission Optimization Mechanism (MTOM)</li></ul><h5
id="Index-OpenAPISpecification(OAS)Support">OpenAPI Specification (OAS)
Support</h5><ul><li>OAS 2.0 (classic Swagger specification)</li><li>OAS 3.0.x
(new revised specification)</li></ul><h3
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple
Tr
ansports, Protocol Bindings, Data Bindings, and
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via
the <a shape="rect" class="external-link"
href="http://camel.apache.org/camel-transport-for-cxf.html">Camel transport for
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP,
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans,
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON,
FastInfoset</li><li>Extensibility API allows additional bindings for CXF,
enabling additional message format support such as CORBA/IIOP</li></ul><h3
id="Index-FlexibleDeployment">Flexible Deployment</h3><ul><li>Lightweight
containers: deploy services in Jetty, Tomcat or Spring-based
containers</li><li>JBI integration: deploy as a service engine in a JBI
container such as ServiceMix, OpenESB or Petals</li><li>Java EE integration:
deploy services in Java EE application servers such as Apache Geronimo, JOnAS,
Redhat JBoss, OC
4J, Oracle WebLogic, and IBM WebSphere</li><li>Standalone Java
client/server</li></ul><h3
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS
for RESTful clients</li><li>Support for wrapped and non-wrapped
styles</li><li>XML messaging API</li><li>Support for JavaScript and ECMAScript
4 XML (E4X) - both client and server</li><li>Support for CORBA</li><li>Support
for JBI with ServiceMix</li></ul><h3
id="Index-Tooling">Tooling</h3><ul><li>Generating Code: WSDL to Java, WSDL to
JavaScript, Java to JavaScript</li><li>Generating WSDL: Java to WSDL, XSD to
WSDL, IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: WSDL to SOAP, WSDL to
CORBA, WSDL to service</li><li>Generating Support Files: WSDL to
IDL</li><li>Validating Files: WSDL Validation</l
i></ul><h2 id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is
currently under heavy development. To get involved you can <a shape="rect"
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab
the code from the <a shape="rect" href="source-repository.html">Source
Repository</a>. You also need to read about <a shape="rect"
href="building.html">Building</a> CXF. For Eclipse users, you should read about
<a shape="rect" href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
</div>
<!-- Content -->
</td>
Added:
websites/production/cxf/content/security-advisories.data/CVE-2026-65583.txt
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-65583.txt
Thu Aug 6 11:43:11 2026 (r1093641)
@@ -0,0 +1,23 @@
+CVE-2026-65583: Apache CXF: Self-issued ID token claims validation skipped
+
+Severity: low
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-sso-oidc) 4.2.0 before 4.2.3
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-sso-oidc) 4.0.0 before 4.1.8
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-sso-oidc) before 3.6.12
+
+Description:
+
+Apache CXF’s OIDC relying-party token validation could accept self-issued ID
tokens without enforcing required claim checks (issuer/subject/audience/time
and sub_jwk binding), enabling authentication bypass with crafted tokens.
However, note that self-issued ID tokens are not accepted by default in the
validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or
3.6.12, which fixes this issue.
+
+Credit:
+
+Guanping Zhang reported this vulnerability. (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-65583
+
Added:
websites/production/cxf/content/security-advisories.data/CVE-2026-68079.txt
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-68079.txt
Thu Aug 6 11:43:11 2026 (r1093641)
@@ -0,0 +1,23 @@
+CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited
authorization code replay
+
+Severity: low
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.3
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.0.0 before 4.1.8
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 3.6.12
+
+Description:
+
+In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization
code can be redeemed an unlimited number of times due to a flaw in the
implementation of the removeCodeGrant functionality. This violates the RFC
requirement that "The authorization code MUST NOT be used more than once."
Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which
fix this issue.
+
+Credit:
+
+Guanping Zhang reported this vulnerability (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-68079
+
Added:
websites/production/cxf/content/security-advisories.data/CVE-2026-68481.txt
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-68481.txt
Thu Aug 6 11:43:11 2026 (r1093641)
@@ -0,0 +1,23 @@
+CVE-2026-68481: Apache CXF: Revocation bypass in
DefaultEncryptingOAuthDataProvider
+
+Severity: low
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.3
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.0.0 before 4.1.8
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 3.6.12
+
+Description:
+
+In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens
still decrypt successfully, and TokenIntrospectionService reports active:true.
The same applies to refresh tokens. This violates the RFC stipulations that
'The authorization server MUST invalidate the token.' and 'introspection of a
revoked token MUST return {"active":false}'. Users are recommended to upgrade
to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
+
+Credit:
+
+Guanping Zhang reported this vulnerability (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-68481
+
Modified: websites/production/cxf/content/security-advisories.html
==============================================================================
--- websites/production/cxf/content/security-advisories.html Thu Aug 6
10:43:11 2026 (r1093640)
+++ websites/production/cxf/content/security-advisories.html Thu Aug 6
11:43:11 2026 (r1093641)
@@ -99,7 +99,7 @@ Apache CXF -- Security Advisories
<td height="100%">
<!-- Content -->
<div class="wiki-content">
-<div id="ConfluenceContent"><p><span style="color:var(--ds-text,#333333);">For
information on how to report a new security problem please
see<span> </span></span><a shape="rect" class="external-link"
href="https://www.apache.org/security/" style="text-decoration:
none;">here</a><span
style="color:var(--ds-text,#333333);">.<span> </span></span></p><h3
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2026-44417.txt?version=1&modificationDate=1779445819000&api=v2"
data-linked-resource-id="429064531" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-44417</a>: Apache CXF:
Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to
RCE)</li><li><a shape="rect" hr
ef="security-advisories.data/CVE-2026-44618.txt?version=1&modificationDate=1779445877000&api=v2"
data-linked-resource-id="429064532" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-44618</a>: Apache CXF: XXE
vulnerability in WS-Transfer functionality</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-44930.txt?version=1&modificationDate=1779445722000&api=v2"
data-linked-resource-id="429064529" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-44930</a>: Apache C
XF: LDAP Injection vulnerability in XKMS LDAP Repository</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-49875.txt?version=1&modificationDate=1781192084000&api=v2"
data-linked-resource-id="430408836" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-49875</a>: Apache CXF: XML
External Entity (XXE) Injection in W3CMultiSchemaFactory and
EndpointReferenceUtils </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50623.txt?version=1&modificationDate=1781192231000&api=v2"
data-linked-resource-id="430408838" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text
File" data-linked-resource-content-type=
"text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50623</a>: Apache CXF:
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50627.txt?version=1&modificationDate=1781192281000&api=v2"
data-linked-resource-id="430408839" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50627</a>: Apache CXF:
OAuth2: Missing JWT Audience and Issuer Validation in Access Token
Validator</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50628.txt?version=1&modificationDate=1781192316000&api=v2"
data-linked-resource-id="430408840" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50628.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50628</a>: Apache CXF:
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50629.txt?version=1&modificationDate=1781192369000&api=v2"
data-linked-resource-id="430408842" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50629</a>: Apache CXF:
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50630.txt?version=1&modificationDate=1781192413000&api=v2"
data-link
ed-resource-id="430408843" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50630</a>: Apache CXF:
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm
Injection </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50631.txt?version=1&modificationDate=1781192445000&api=v2"
data-linked-resource-id="430408844" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50631</a>: Apache CXF:
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50632.txt?version=2&modificationDate=1781197304000&api=v2"
data-linked-resource-id="430408845" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50632.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50632</a>: Apache CXF:
JNDI Injection Vulnerability in JMSConfigFactory</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50633.txt?version=1&modificationDate=1781192513000&api=v2"
data-linked-resource-id="430408847" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50633</a>: Apac
he CXF: JNDI Injection vulnerability in
DispatchMDBMessageListenerImpl</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50634.txt?version=1&modificationDate=1781192545000&api=v2"
data-linked-resource-id="430408848" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50634.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50634</a>: Apache CXF: WS
JSON request filter trusts metadata from an unvalidated first signature
entry</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50645.txt?version=3&modificationDate=1781197687000&api=v2"
data-linked-resource-id="430408849" data-linked-resource-version="3"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50645.txt" data-nice-type="Text
File" data-linked-resource-content-type
="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-50645</a>: Apache CXF: No
restriction on attachment headers per message</li><li
data-uuid="49670750-d78a-4fe2-a830-cc372623486a"><a shape="rect"
href="security-advisories.data/CVE-2026-54225.txt?version=1&modificationDate=1786010395000&api=v2"
data-linked-resource-id="446071159" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-54225.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-54225</a>: Apache CXF:
Denial of Service attack via large attachments</li><li
data-uuid="4d3b7d2a-2f95-4a2a-a0a4-16f3020d96a7"><a shape="rect"
href="security-advisories.data/CVE-2026-57817.txt?version=1&modificationDate=1786011692000&api=v2"
data-linked-resource-id="446071172" data-linked
-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-57817.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-57817</a>: Apache CXF: The
authorization code hash (c_hash) is not enforced for the hybrid OIDC
flow</li><li data-uuid="421dab32-bb7b-4d04-a713-bf4012dab629"><a shape="rect"
href="security-advisories.data/CVE-2026-57818.txt?version=1&modificationDate=1786011946000&api=v2"
data-linked-resource-id="446071174" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-57818.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-57818</a>: Apache CXF:
OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvide
r</li><li data-uuid="9d893f5b-4577-4891-9f8a-c2a20c2a5a4d"><a shape="rect"
href="security-advisories.data/CVE-2026-57819.txt?version=1&modificationDate=1786010722000&api=v2"
data-linked-resource-id="446071161" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-57819.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-57819</a>: Apache CXF: No
default restriction on the amount of form parameters per message</li><li
data-uuid="37f9ccab-4420-47c2-9438-12b46f6066e1"><a shape="rect"
href="security-advisories.data/CVE-2026-61466.txt?version=1&modificationDate=1786012193000&api=v2"
data-linked-resource-id="446071176" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-61466.txt" data-nice-type="Text
File" data-linked-resou
rce-content-type="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-61466</a>: Apache CXF:
OAuth2 Dynamic Client Registration Scope Self-Escalation</li><li
data-uuid="7c0ccedd-3bf8-4f26-993b-1ee8e96c74a4"><a shape="rect"
href="security-advisories.data/CVE-2026-63687.txt?version=2&modificationDate=1786012916381&api=v2"
data-linked-resource-id="446071178" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-63687.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-63687</a>: Apache CXF:
JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters</li><li
data-uuid="497c4f06-b436-4629-aa2d-e022a5268c29"><a shape="rect"
href="security-advisories.data/CVE-2026-64958.txt?version=1&modificationDate=1786011007000&api=v2
" data-linked-resource-id="446071164" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-64958.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-64958</a>: Apache CXF:
Denial of service via message header attachments</li><li
data-uuid="b0b1eaaa-380b-4004-acbf-c135ef8b97e1"><a shape="rect"
href="security-advisories.data/CVE-2026-65432.txt?version=1&modificationDate=1786011271000&api=v2"
data-linked-resource-id="446071166" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-65432.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-65432</a>: Apache CXF: XXE
via WSDL/XSD import parsing</li><li data-uui
d="2693b482-0db3-4743-aa55-aec24d4be213"><a shape="rect"
href="security-advisories.data/CVE-2026-66909.txt?version=2&modificationDate=1786011477000&api=v2"
data-linked-resource-id="446071168" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-66909.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2026-66909</a>: Apache CXF:
Unsafe deserialization of inbound JMS ObjectMessage</li></ul><h3
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2025-23184.txt?version=2&modificationDate=1737381863000&api=v2"
data-linked-resource-id="340036025" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" da
ta-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2025-23184</a>: Apache CXF:
Denial of Service vulnerability with temporary files </li><li><a
shape="rect"
href="security-advisories.data/CVE-2025-48795.txt?version=1&modificationDate=1752578416000&api=v2"
data-linked-resource-id="373886120" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-48795.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2025-48795</a>: Apache CXF:
Denial of Service and sensitive data exposure in logs </li><li><a
shape="rect"
href="security-advisories.data/CVE-2025-48913.txt?version=1&modificationDate=1754576095000&api=v2"
data-linked-resource-id="373887565" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-resource-default-a
lias="CVE-2025-48913.txt" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2025-48913</a>: Apache CXF:
Untrusted JMS configuration can lead to RCE </li></ul><h3
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2024-28752.txt?version=2&modificationDate=1710431346000&api=v2"
data-linked-resource-id="296290905" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2024-28752</a>: Apache CXF SSRF
Vulnerability using the Aegis databinding </li><li><a shape="rect"
href="security-advisories.data/CVE-2024-29736.txt?version=1&modificationDate=1721314668000&api=v2"
da
ta-linked-resource-id="315493016" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2024-29736</a>: SSRF
vulnerability via WADL stylesheet parameter</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-32007.txt?version=1&modificationDate=1721314761000&api=v2"
data-linked-resource-id="315493017" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2024-32007</a>: Apache CXF
Denial of Service vulnerability in JOSE</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-41172.txt?
version=1&modificationDate=1721314821000&api=v2"
data-linked-resource-id="315493018" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2024-41172</a>: Unrestricted
memory consumption in CXF HTTP clients</li></ul><h3
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2022-46363.txt?version=1&modificationDate=1670942001000&api=v2"
data-linked-resource-id="235836918" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2022-46363</a>: Apache CXF d
irectory listing / code exfiltration</li><li><a shape="rect"
href="security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944473000&api=v2"
data-linked-resource-id="235836926" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2022-46364</a>: Apache CXF SSRF
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&modificationDate=1623835370000&api=v2"
data-linked-resource-id="181310680" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-30468.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-con
tainer-id="27837502"
data-linked-resource-container-version="77">CVE-2021-30468</a>: Apache CXF
Denial of service vulnerability in parsing JSON via
JsonMapObjectReaderWriter</li><li><a shape="rect"
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&modificationDate=1617355743000&api=v2"
data-linked-resource-id="177049091" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-22696.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2021-22696</a>: OAuth 2
authorization service vulnerable to DDos attacks</li></ul><h3
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&modificationDate=1605183671000&api=v2"
data-linked-resource-id="165225095" data-linked-resource-version="1"
data-linked-resource-type
="attachment" data-linked-resource-default-alias="CVE-2020-13954.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2020-13954</a>: Apache CXF
Reflected XSS in the services listing page via the styleSheetPath</li><li><a
shape="rect"
href="security-advisories.data/CVE-2020-1954.txt.asc?version=1&modificationDate=1585730169000&api=v2"
data-linked-resource-id="148645097" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2020-1954</a>: Apache CXF JMX
Integration is vulnerable to a MITM attack</li></ul><h3
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2019-17573.t
xt.asc?version=2&modificationDate=1584610519000&api=v2"
data-linked-resource-id="145722246" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-17573.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2019-17573</a>: Apache CXF
Reflected XSS in the services listing page</li><li><a shape="rect"
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&modificationDate=1579178393000&api=v2"
data-linked-resource-id="145722244" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12423.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2019-12423</a>: Apache CXF
OpenId Connect JWK Keys service
returns private/secret credentials if configured with a jwk
keystore</li><li><a shape="rect"
href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&modificationDate=1572961201000&api=v2"
data-linked-resource-id="135859612" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12419.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2019-12419</a>: Apache CXF
OpenId Connect token service does not properly validate the clientId</li><li><a
shape="rect"
href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&modificationDate=1572957147000&api=v2"
data-linked-resource-id="135859607" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12406.txt.asc"
data-nice-type="Text File" data-linked-resource-content-ty
pe="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2019-12406</a>: Apache CXF does
not restrict the number of message attachments</li></ul><h3
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&modificationDate=1530184663000&api=v2"
data-linked-resource-id="87296645" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2018-8039</a>: Apache CXF TLS
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&modificationDate=1530712328000&api=v2"
data-linked-resource-id="87297524" data-linked-resource-ver
sion="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8038.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2018-8038</a>: Apache CXF Fediz
is vulnerable to DTD based XML attacks</li></ul><h3
id="SecurityAdvisories-2017">2017</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&modificationDate=1512037276000&api=v2"
data-linked-resource-id="74688816" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12631.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2017-12631</a>: CSRF
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect"
href="security-advisories.data/
CVE-2017-12624.txt.asc?version=1&modificationDate=1510661632000&api=v2"
data-linked-resource-id="74687100" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12624.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2017-12624</a>: Apache CXF web
services that process attachments are vulnerable to Denial of Service (DoS)
attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&modificationDate=1494949377000&api=v2"
data-linked-resource-id="70255583" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-
2017-7662</a>: The Apache CXF Fediz OIDC Client Registration Service is
vulnerable to CSRF attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&modificationDate=1494949364000&api=v2"
data-linked-resource-id="70255582" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7661.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2017-7661</a>: The Apache CXF
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113000&api=v2"
data-linked-resource-id="69406543" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text
File" data-linke
d-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2017-5656</a>: Apache CXF's
STSClient uses a flawed way of caching tokens that are associated with
delegation tokens.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&modificationDate=1492515074000&api=v2"
data-linked-resource-id="69406542" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2017-5653</a>: Apache CXF
JAX-RS XML Security streaming clients do not validate that the service response
was signed or encrypted.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&modificationDate=1487590374000&api=v2"
data-linked-resou
rce-id="68715428" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-3156.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2017-3156</a>: Apache CXF
OAuth2 Hawk and JOSE MAC Validation code is vulnerable to the timing
attacks</li></ul><h3 id="SecurityAdvisories-2016">2016</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635454" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2016-8739</a>: Atom entity
provider of Apache CXF JAX-RS is
vulnerable to XXE</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-6812.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635455" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2016-6812</a>: XSS risk in
Apache CXF FormattedServiceListWriter when a request URL contains matrix
parameters</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&modificationDate=1473350153000&api=v2"
data-linked-resource-id="65869472" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data-linked-resource-contai
ner-id="27837502"
data-linked-resource-container-version="77">CVE-2016-4464</a>: Apache CXF Fediz
application plugins do not match the SAML AudienceRestriction values against
the list of configured audience URIs</li></ul><h3
id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&modificationDate=1447433340000&api=v2"
data-linked-resource-id="61328642" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2015-5253</a>: Apache CXF SAML
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&modificationDate=1440598018000&api=v2"
data-linked-resource-id="61316328" data-linked-resou
rce-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5175.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2015-5175</a>: Apache CXF Fediz
application plugins are vulnerable to Denial of Service (DoS)
attacks</li></ul><h3 id="SecurityAdvisories-2014">2014</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&modificationDate=1419245371000&api=v2"
data-linked-resource-id="51183657" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-3577</a>: Apache CXF SSL
hostname verification bypass</li><li><a shape="rect" href="securit
y-advisories.data/CVE-2014-3566.txt.asc?version=1&modificationDate=1418740474000&api=v2"
data-linked-resource-id="50561078" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">Note on CVE-2014-3566</a>: SSL 3.0
support in Apache CXF, aka the "POODLE" attack.</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&modificationDate=1414169368000&api=v2"
data-linked-resource-id="47743195" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-3623</a>: Apache
CXF does not properly enforce the security semantics of SAML
SubjectConfirmation methods when used with the TransportBinding</li><li><a
shape="rect"
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&modificationDate=1414169326000&api=v2"
data-linked-resource-id="47743194" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3584.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-3584</a>: Apache CXF
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS)
attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&modificationDate=1398873370000&api=v2"
data-linked-resource-id="40895138" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-ni
ce-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-0109</a>: HTML content
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&modificationDate=1398873378000&api=v2"
data-linked-resource-id="40895139" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-0110</a>: Large invalid
content could cause temporary space to fill</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&modificationDate=1398873385000&api=v2"
data-linked-resource-id="40895140" data-linked-resource-version="1"
data-linked-resource
-type="attachment" data-linked-resource-default-alias="CVE-2014-0034.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-0034</a>: The
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a
shape="rect"
href="security-advisories.data/CVE-2014-0035.txt.asc?version=1&modificationDate=1398873391000&api=v2"
data-linked-resource-id="40895141" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2014-0035</a>: UsernameTokens
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect"
href="security-advisories.da
ta/CVE-2013-2160.txt.asc?version=1&modificationDate=1372324301000&api=v2"
data-linked-resource-id="33095710" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="77">CVE-2013-2160</a> - Denial of
Service Attacks on Apache CXF</li><li><a shape="rect"
href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML Encryption backwards
compatibility attack on Apache CXF.</li><li><a shape="rect"
href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication bypass in the case
of WS-SecurityPolicy enabled plaintext UsernameTokens.</li></ul><h3
id="SecurityAdvisories-2012">2012</h3><ul><li><a shape="rect"
href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor always allows
HTTP Get requests from browser.</li><li><a shape="rect" href="note-on-cve-
2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher attack against
distributed symmetric key in WS-Security.</li><li><a shape="rect"
href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is vulnerable to SOAP
Action spoofing attacks on Document Literal web services.</li><li><a
shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> - Apache CXF does not
verify that elements were signed or encrypted by a particular Supporting
Token.</li><li><a shape="rect" href="cve-2012-2378.html">CVE-2012-2378</a> -
Apache CXF does not pick up some child policies of WS-SecurityPolicy 1.1
SupportingToken policy assertions on the client side.</li><li><a shape="rect"
href="note-on-cve-2011-1096.html">Note on CVE-2011-1096</a> - XML Encryption
flaw / Character pattern encoding attack.</li><li><a shape="rect"
href="cve-2012-0803.html">CVE-2012-0803</a> - Apache CXF does not validate
UsernameToken policies correctly.</li></ul><h3
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect" cl
ass="external-link"
href="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf">CVE-2010-2076</a>
- DTD based XML attacks.</li></ul><p><br clear="none"></p></div>
+<div id="ConfluenceContent"><p><span style="color:var(--ds-text,#333333);">For
information on how to report a new security problem please
see<span> </span></span><a shape="rect" class="external-link"
href="https://www.apache.org/security/" style="text-decoration:
none;">here</a><span
style="color:var(--ds-text,#333333);">.<span> </span></span></p><h3
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2026-44417.txt?version=1&modificationDate=1779445819000&api=v2"
data-linked-resource-id="429064531" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-44417</a>: Apache CXF:
Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to
RCE)</li><li><a shape="rect" hr
ef="security-advisories.data/CVE-2026-44618.txt?version=1&modificationDate=1779445877000&api=v2"
data-linked-resource-id="429064532" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-44618</a>: Apache CXF: XXE
vulnerability in WS-Transfer functionality</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-44930.txt?version=1&modificationDate=1779445722000&api=v2"
data-linked-resource-id="429064529" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-44930</a>: Apache C
XF: LDAP Injection vulnerability in XKMS LDAP Repository</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-49875.txt?version=1&modificationDate=1781192084000&api=v2"
data-linked-resource-id="430408836" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-49875</a>: Apache CXF: XML
External Entity (XXE) Injection in W3CMultiSchemaFactory and
EndpointReferenceUtils </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50623.txt?version=1&modificationDate=1781192231000&api=v2"
data-linked-resource-id="430408838" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text
File" data-linked-resource-content-type=
"text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50623</a>: Apache CXF:
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50627.txt?version=1&modificationDate=1781192281000&api=v2"
data-linked-resource-id="430408839" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50627</a>: Apache CXF:
OAuth2: Missing JWT Audience and Issuer Validation in Access Token
Validator</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50628.txt?version=1&modificationDate=1781192316000&api=v2"
data-linked-resource-id="430408840" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50628.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50628</a>: Apache CXF:
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50629.txt?version=1&modificationDate=1781192369000&api=v2"
data-linked-resource-id="430408842" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50629</a>: Apache CXF:
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50630.txt?version=1&modificationDate=1781192413000&api=v2"
data-link
ed-resource-id="430408843" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50630</a>: Apache CXF:
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm
Injection </li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50631.txt?version=1&modificationDate=1781192445000&api=v2"
data-linked-resource-id="430408844" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50631</a>: Apache CXF:
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a
shape="rect"
href="security-advisories.data/CVE-2026-50632.txt?version=2&modificationDate=1781197304000&api=v2"
data-linked-resource-id="430408845" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50632.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50632</a>: Apache CXF:
JNDI Injection Vulnerability in JMSConfigFactory</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50633.txt?version=1&modificationDate=1781192513000&api=v2"
data-linked-resource-id="430408847" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50633</a>: Apac
he CXF: JNDI Injection vulnerability in
DispatchMDBMessageListenerImpl</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50634.txt?version=1&modificationDate=1781192545000&api=v2"
data-linked-resource-id="430408848" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50634.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50634</a>: Apache CXF: WS
JSON request filter trusts metadata from an unvalidated first signature
entry</li><li><a shape="rect"
href="security-advisories.data/CVE-2026-50645.txt?version=3&modificationDate=1781197687000&api=v2"
data-linked-resource-id="430408849" data-linked-resource-version="3"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-50645.txt" data-nice-type="Text
File" data-linked-resource-content-type
="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-50645</a>: Apache CXF: No
restriction on attachment headers per message</li><li
data-uuid="49670750-d78a-4fe2-a830-cc372623486a"><a shape="rect"
href="security-advisories.data/CVE-2026-54225.txt?version=1&modificationDate=1786010395000&api=v2"
data-linked-resource-id="446071159" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-54225.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-54225</a>: Apache CXF:
Denial of Service attack via large attachments</li><li
data-uuid="4d3b7d2a-2f95-4a2a-a0a4-16f3020d96a7"><a shape="rect"
href="security-advisories.data/CVE-2026-57817.txt?version=1&modificationDate=1786011692000&api=v2"
data-linked-resource-id="446071172" data-linked
-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-57817.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-57817</a>: Apache CXF: The
authorization code hash (c_hash) is not enforced for the hybrid OIDC
flow</li><li data-uuid="421dab32-bb7b-4d04-a713-bf4012dab629"><a shape="rect"
href="security-advisories.data/CVE-2026-57818.txt?version=1&modificationDate=1786011946000&api=v2"
data-linked-resource-id="446071174" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-57818.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-57818</a>: Apache CXF:
OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvide
r</li><li data-uuid="9d893f5b-4577-4891-9f8a-c2a20c2a5a4d"><a shape="rect"
href="security-advisories.data/CVE-2026-57819.txt?version=1&modificationDate=1786010722000&api=v2"
data-linked-resource-id="446071161" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-57819.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-57819</a>: Apache CXF: No
default restriction on the amount of form parameters per message</li><li
data-uuid="37f9ccab-4420-47c2-9438-12b46f6066e1"><a shape="rect"
href="security-advisories.data/CVE-2026-61466.txt?version=1&modificationDate=1786012193000&api=v2"
data-linked-resource-id="446071176" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-61466.txt" data-nice-type="Text
File" data-linked-resou
rce-content-type="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-61466</a>: Apache CXF:
OAuth2 Dynamic Client Registration Scope Self-Escalation</li><li
data-uuid="7c0ccedd-3bf8-4f26-993b-1ee8e96c74a4"><a shape="rect"
href="security-advisories.data/CVE-2026-63687.txt?version=2&modificationDate=1786012916000&api=v2"
data-linked-resource-id="446071178" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-63687.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-63687</a>: Apache CXF:
JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters</li><li
data-uuid="497c4f06-b436-4629-aa2d-e022a5268c29"><a shape="rect"
href="security-advisories.data/CVE-2026-64958.txt?version=1&modificationDate=1786011007000&api=v2
" data-linked-resource-id="446071164" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-64958.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-64958</a>: Apache CXF:
Denial of service via message header attachments</li><li
data-uuid="b0b1eaaa-380b-4004-acbf-c135ef8b97e1"><a shape="rect"
href="security-advisories.data/CVE-2026-65432.txt?version=1&modificationDate=1786011271000&api=v2"
data-linked-resource-id="446071166" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-65432.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-65432</a>: Apache CXF: XXE
via WSDL/XSD import parsing</li><li data-uui
d="7f19a0df-3457-45ef-bd8f-cfe71b66943c"><a shape="rect"
href="security-advisories.data/CVE-2026-65583.txt?version=1&modificationDate=1786013097000&api=v2"
data-linked-resource-id="446071184" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-65583.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-65583</a>: Apache CXF:
Self-issued ID token claims validation skipped</li><li
data-uuid="2693b482-0db3-4743-aa55-aec24d4be213"><a shape="rect"
href="security-advisories.data/CVE-2026-66909.txt?version=2&modificationDate=1786011477000&api=v2"
data-linked-resource-id="446071168" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-66909.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data-link
ed-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-66909</a>: Apache CXF:
Unsafe deserialization of inbound JMS ObjectMessage</li><li
data-uuid="89ccf4e0-27b8-46a2-b30b-c382bf070593"><a shape="rect"
href="security-advisories.data/CVE-2026-68079.txt?version=1&modificationDate=1786013245000&api=v2"
data-linked-resource-id="446071186" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-68079.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-68079</a>: Apache CXF:
DefaultEncryptingCodeDataProvider allows unlimited authorization code
replay</li><li data-uuid="ab47b81c-be3b-460d-acdb-cb9a11f85d57"><a shape="rect"
href="security-advisories.data/CVE-2026-68481.txt?version=3&modificationDate=1786013432000&api=v2"
data-linked-resource-id="446071188" d
ata-linked-resource-version="3" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2026-68481.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2026-68481</a>: Apache CXF:
Revocation bypass in DefaultEncryptingOAuthDataProvider</li></ul><h3
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2025-23184.txt?version=2&modificationDate=1737381863000&api=v2"
data-linked-resource-id="340036025" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2025-23184</a>: Apache CXF:
Denial of Service vulnerability with temporary files </li><li><a shape="r
ect"
href="security-advisories.data/CVE-2025-48795.txt?version=1&modificationDate=1752578416000&api=v2"
data-linked-resource-id="373886120" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-48795.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2025-48795</a>: Apache CXF:
Denial of Service and sensitive data exposure in logs </li><li><a
shape="rect"
href="security-advisories.data/CVE-2025-48913.txt?version=1&modificationDate=1754576095000&api=v2"
data-linked-resource-id="373887565" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2025
-48913</a>: Apache CXF: Untrusted JMS configuration can lead to
RCE </li></ul><h3 id="SecurityAdvisories-2024">2024</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2024-28752.txt?version=2&modificationDate=1710431346000&api=v2"
data-linked-resource-id="296290905" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2024-28752</a>: Apache CXF SSRF
Vulnerability using the Aegis databinding </li><li><a shape="rect"
href="security-advisories.data/CVE-2024-29736.txt?version=1&modificationDate=1721314668000&api=v2"
data-linked-resource-id="315493016" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text
File" data-lin
ked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2024-29736</a>: SSRF
vulnerability via WADL stylesheet parameter</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-32007.txt?version=1&modificationDate=1721314761000&api=v2"
data-linked-resource-id="315493017" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2024-32007</a>: Apache CXF
Denial of Service vulnerability in JOSE</li><li><a shape="rect"
href="security-advisories.data/CVE-2024-41172.txt?version=1&modificationDate=1721314821000&api=v2"
data-linked-resource-id="315493018" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linked-resource-default-ali
as="CVE-2024-41172.txt" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2024-41172</a>: Unrestricted
memory consumption in CXF HTTP clients</li></ul><h3
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2022-46363.txt?version=1&modificationDate=1670942001000&api=v2"
data-linked-resource-id="235836918" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2022-46363</a>: Apache CXF
directory listing / code exfiltration</li><li><a shape="rect"
href="security-advisories.data/CVE-2022-46364.txt?version=1&modificationDate=1670944473000&api=v2"
data-linked-resource-id="2358
36926" data-linked-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2022-46364</a>: Apache CXF SSRF
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&modificationDate=1623835370000&api=v2"
data-linked-resource-id="181310680" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-30468.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2021-30468</a>: Apache CXF
Denial of service vulnerability in parsing JSON via
JsonMapObjectReaderWriter</li><li><a shape="rect"
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&modificationDate=1617355743000&api=v2"
data-linked-resource-id="177049091" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2021-22696.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2021-22696</a>: OAuth 2
authorization service vulnerable to DDos attacks</li></ul><h3
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&modificationDate=1605183671000&api=v2"
data-linked-resource-id="165225095" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-13954.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502" data
-linked-resource-container-version="82">CVE-2020-13954</a>: Apache CXF
Reflected XSS in the services listing page via the styleSheetPath</li><li><a
shape="rect"
href="security-advisories.data/CVE-2020-1954.txt.asc?version=1&modificationDate=1585730169000&api=v2"
data-linked-resource-id="148645097" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2020-1954</a>: Apache CXF JMX
Integration is vulnerable to a MITM attack</li></ul><h3
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&modificationDate=1584610519000&api=v2"
data-linked-resource-id="145722246" data-linked-resource-version="2"
data-linked-resource-type="attachment" data-linked-resource-defa
ult-alias="CVE-2019-17573.txt.asc" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2019-17573</a>: Apache CXF
Reflected XSS in the services listing page</li><li><a shape="rect"
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&modificationDate=1579178393000&api=v2"
data-linked-resource-id="145722244" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12423.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2019-12423</a>: Apache CXF
OpenId Connect JWK Keys service returns private/secret credentials if
configured with a jwk keystore</li><li><a shape="rect"
href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&modificationDate=1572961201000&
api=v2" data-linked-resource-id="135859612" data-linked-resource-version="2"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12419.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2019-12419</a>: Apache CXF
OpenId Connect token service does not properly validate the clientId</li><li><a
shape="rect"
href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&modificationDate=1572957147000&api=v2"
data-linked-resource-id="135859607" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2019-12406.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2019-12406</a>: Apache CXF does
not restrict the number of message attachments</li></ul>
<h3 id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&modificationDate=1530184663000&api=v2"
data-linked-resource-id="87296645" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2018-8039</a>: Apache CXF TLS
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&modificationDate=1530712328000&api=v2"
data-linked-resource-id="87297524" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2018-8038.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data-linked-reso
urce-container-id="27837502"
data-linked-resource-container-version="82">CVE-2018-8038</a>: Apache CXF Fediz
is vulnerable to DTD based XML attacks</li></ul><h3
id="SecurityAdvisories-2017">2017</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&modificationDate=1512037276000&api=v2"
data-linked-resource-id="74688816" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-12631.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-12631</a>: CSRF
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&modificationDate=1510661632000&api=v2"
data-linked-resource-id="74687100" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-linke
d-resource-default-alias="CVE-2017-12624.txt.asc" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-12624</a>: Apache CXF web
services that process attachments are vulnerable to Denial of Service (DoS)
attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&modificationDate=1494949377000&api=v2"
data-linked-resource-id="70255583" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-7662</a>: The Apache CXF
Fediz OIDC Client Registration Service is vulnerable to CSRF
attacks.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&modifi
cationDate=1494949364000&api=v2" data-linked-resource-id="70255582"
data-linked-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-7661.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-7661</a>: The Apache CXF
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a
shape="rect"
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113000&api=v2"
data-linked-resource-id="69406543" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-5656</a>: Apache CXF's
STSClient uses a flawed way of caching
tokens that are associated with delegation tokens.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&modificationDate=1492515074000&api=v2"
data-linked-resource-id="69406542" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-5653</a>: Apache CXF
JAX-RS XML Security streaming clients do not validate that the service response
was signed or encrypted.</li><li><a shape="rect"
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&modificationDate=1487590374000&api=v2"
data-linked-resource-id="68715428" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2017-3156.txt.asc" data-nice-type="Text
File" data-linked-resource-
content-type="text/plain" data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2017-3156</a>: Apache CXF
OAuth2 Hawk and JOSE MAC Validation code is vulnerable to the timing
attacks</li></ul><h3 id="SecurityAdvisories-2016">2016</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635454" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2016-8739</a>: Atom entity
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-6812.txt.asc?version=1&modificationDate=1482164360000&api=v2"
data-linked-resource-id="67635455" data-linke
d-resource-version="1" data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2016-6812</a>: XSS risk in
Apache CXF FormattedServiceListWriter when a request URL contains matrix
parameters</li><li><a shape="rect"
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&modificationDate=1473350153000&api=v2"
data-linked-resource-id="65869472" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2016-4464</a>: Apache CXF Fediz
application plugins do not match the SAML AudienceRestriction values against
the list of configured
audience URIs</li></ul><h3 id="SecurityAdvisories-2015">2015</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&modificationDate=1447433340000&api=v2"
data-linked-resource-id="61328642" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2015-5253</a>: Apache CXF SAML
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&modificationDate=1440598018000&api=v2"
data-linked-resource-id="61316328" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2015-5175.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain" data-link
ed-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2015-5175</a>: Apache CXF Fediz
application plugins are vulnerable to Denial of Service (DoS)
attacks</li></ul><h3 id="SecurityAdvisories-2014">2014</h3><ul><li><a
shape="rect"
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&modificationDate=1419245371000&api=v2"
data-linked-resource-id="51183657" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-3577</a>: Apache CXF SSL
hostname verification bypass</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&modificationDate=1418740474000&api=v2"
data-linked-resource-id="50561078" data-linked-resource-version="1"
data-linked-resource-type="attac
hment" data-linked-resource-default-alias="CVE-2014-3566.txt.asc"
data-nice-type="Text File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">Note on CVE-2014-3566</a>: SSL 3.0
support in Apache CXF, aka the "POODLE" attack.</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&modificationDate=1414169368000&api=v2"
data-linked-resource-id="47743195" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-3623</a>: Apache CXF does
not properly enforce the security semantics of SAML SubjectConfirmation methods
when used with the TransportBinding</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-3584.tx
t.asc?version=1&modificationDate=1414169326000&api=v2"
data-linked-resource-id="47743194" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-3584.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-3584</a>: Apache CXF
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS)
attack</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&modificationDate=1398873370000&api=v2"
data-linked-resource-id="40895138" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-0109</a>: HTML content
posted to
SOAP endpoint could cause OOM errors</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&modificationDate=1398873378000&api=v2"
data-linked-resource-id="40895139" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-0110</a>: Large invalid
content could cause temporary space to fill</li><li><a shape="rect"
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&modificationDate=1398873385000&api=v2"
data-linked-resource-id="40895140" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0034.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-0034</a>: The
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a
shape="rect"
href="security-advisories.data/CVE-2014-0035.txt.asc?version=1&modificationDate=1398873391000&api=v2"
data-linked-resource-id="40895141" data-linked-resource-version="1"
data-linked-resource-type="attachment"
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text
File" data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2014-0035</a>: UsernameTokens
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect"
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&modificationDate=1372324301000&api=v2"
data-linked-resource-id="33095710" data-linked-resource-version="1"
data-linked-resource-type="attachment" data-lin
ked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text File"
data-linked-resource-content-type="text/plain"
data-linked-resource-container-id="27837502"
data-linked-resource-container-version="82">CVE-2013-2160</a> - Denial of
Service Attacks on Apache CXF</li><li><a shape="rect"
href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML Encryption backwards
compatibility attack on Apache CXF.</li><li><a shape="rect"
href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication bypass in the case
of WS-SecurityPolicy enabled plaintext UsernameTokens.</li></ul><h3
id="SecurityAdvisories-2012">2012</h3><ul><li><a shape="rect"
href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor always allows
HTTP Get requests from browser.</li><li><a shape="rect"
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher
attack against distributed symmetric key in WS-Security.</li><li><a
shape="rect" href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF
is vulnerable to SOAP Action spoofing attacks on Document Literal web
services.</li><li><a shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> -
Apache CXF does not verify that elements were signed or encrypted by a
particular Supporting Token.</li><li><a shape="rect"
href="cve-2012-2378.html">CVE-2012-2378</a> - Apache CXF does not pick up some
child policies of WS-SecurityPolicy 1.1 SupportingToken policy assertions on
the client side.</li><li><a shape="rect" href="note-on-cve-2011-1096.html">Note
on CVE-2011-1096</a> - XML Encryption flaw / Character pattern encoding
attack.</li><li><a shape="rect" href="cve-2012-0803.html">CVE-2012-0803</a> -
Apache CXF does not validate UsernameToken policies correctly.</li></ul><h3
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect"
class="external-link"
href="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf">CVE-2010-2076</a>
- DTD based XML attacks.</li></ul><p><br clear="none"></p></div>
</div>
<!-- Content -->
</td>