Author: buildbot
Date: Fri Oct  9 09:43:18 2026
New Revision: 1094223

Log:
Production update by buildbot for cxf

Added:
   websites/production/cxf/content/security-advisories.data/CVE-2026-100227.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-107937.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-107938.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-108039.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-79650.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-86463.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-97468.txt
   websites/production/cxf/content/security-advisories.data/CVE-2026-97791.txt
Modified:
   websites/production/cxf/content/cache/main.pageCache
   websites/production/cxf/content/index.html
   websites/production/cxf/content/security-advisories.html

Modified: websites/production/cxf/content/cache/main.pageCache
==============================================================================
Binary file (source and/or target). No diff available.

Modified: websites/production/cxf/content/index.html
==============================================================================
--- websites/production/cxf/content/index.html  Fri Oct  9 09:04:47 2026        
(r1094222)
+++ websites/production/cxf/content/index.html  Fri Oct  9 09:43:18 2026        
(r1094223)
@@ -99,7 +99,7 @@ Apache CXF -- Index
          <td height="100%">
            <!-- Content -->
            <div class="wiki-content">
-<div id="ConfluenceContent"><h1 
id="Index-ApacheCXF&#8482;:AnOpen-SourceServicesFramework">Apache CXF&#8482;: 
An Open-Source Services Framework</h1><h2 
id="Index-Overview">Overview</h2><p>Apache CXF&#8482; is an open source 
services framework. CXF helps you build and develop services using frontend 
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of 
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a 
variety of transports such as HTTP, JMS or JBI.</p><h2 
id="Index-News">News</h2><h3 
id="Index-October8,2026-ApacheCXF4.2.4,4.1.9and3.6.13released!">October 8, 2026 
- Apache CXF 4.2.4, 4.1.9 and 3.6.13 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 9 JIRA issues were fixed for 4.2.4, 8 JIRA issues 
were fixed for 4.1.9. and&#160; 4 JIRA issues were fixed for 
3.6.13.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 id="Index-Aug
 ust5,2026-ApacheCXF4.2.3,4.1.8and3.6.12released!">August 5, 2026 - Apache CXF 
4.2.3, 4.1.8 and 3.6.12 released!</h3><p>The Apache CXF team is proud to 
announce the availability of our latest patch releases!&#160;</p><p>Over 10 
JIRA issues were fixed for 4.2.3, 6 JIRA issues were fixed for 4.1.8. and&#160; 
4 JIRA issues were fixed for 3.6.12.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><p>These releases contain fixes 
for multiple CVE issues, please see <a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache 
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce 
the availability of our latest patch releases!&#160;</p><p>Over 5 JIRA issues 
were fixed for 4.2.2 and&#160; 4 JIRA issues were fixed for 
4.1.7.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes fo
 r multiple CVE issues, please see <a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2026 - 
Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 15 JIRA issues were fixed for 4.2.1, &#160;10 JIRA 
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for 
3.6.11.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE 
issues, please see&#160;<a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16, 
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache 
CXF team is proud to announce the availability of our latest patch 
releases!&#160;</p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues
  were fixed for 4.1.5, &#160;14 JIRA issues were fixed for 4.0.11, 8 JIRA 
issues were fixed for 3.6.10.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 2025 - 
Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 13 JIRA issues were fixed for 4.1.4,&#160; 11 JIRA 
issues were fixed for 4.0.10, 12 JIRA issues were fixed for 
3.6.9.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 - 
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 10 JIRA 
issues were fixed for 4.1.3 and 4.0.9,&#160;</p><p>6 JIRA issues were fixed for 
3.6.8. These releases contain a fix for a new CVE:<
 /p><ul><li><a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt";>https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 - 
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 16 JIRA 
issues were fixed for 4.1.2,&#160;</p><p>11 JIRA issues were fixed for 4.0.8, 
10 JIRA issues were fixed for 3.6.7.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 - 
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache CXF team 
is proud to announce the availability of our latest patch releases!&#160; Over 
17 JIRA issues were fixed for 4.1.1,&#160;</p><p>14 JIR
 A issues were fixed for 4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA 
issues were fixed for 3.5.11.</p><p>Please note that the CXF 3.5.11 is the last 
release of CXF 3.5.x series</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0 
released!</h3><p>The Apache CXF team is proud to announce the availability of 
CXF 4.1.0! &#160;The 4.1.0 is our first release to feature Jakarta EE 10 
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for 
4.1.0,&#160;</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 - 
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch releases!&#160; Over 29 
JIRA issues were fixed for 4.0.6,&#160;</p><p>25 JIRA issues were fixed for 
3.6.5 and 18 JIRA 
 issues were fixed for 3.5.10.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July 17, 2024 - 
Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 19 JIRA 
issues were fixed for 4.0.5.</p><p>These releases contain fixes for 3 different 
CVEs:</p><ul><li><a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
 are available&#160;<a sha
 pe="rect" href="download.html">here</a>.</p><h3 
id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 12, 2024 - 
Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 28 JIRA 
issues were fixed for 4.0.4.</p><p>These releases contain a fix for a new 
security issue: <a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 - 
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 id="Index-
 June12,2023-ApacheCXF3.6.1and4.0.2released!">June 12, 2023 - Apache CXF 3.6.1 
and 4.0.2 released!</h3><p>The Apache CXF team is proud to announce the 
availability of our latest patch releases!&#160; Over 7 JIRA issues were fixed 
for 4.0.2 and 3.6.1.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache 
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to 
announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Features">Features</h3><p>CXF includes a broad feature set, but it is 
primarily focused on the following areas:</p><ul><li><strong>Web Services 
Standards Support:</strong> CXF supports a variety of web service standards 
including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy
 , WS-ReliableMessaging, WS-Security, WS-SecurityPolicy, 
WS-SecureConverstation, and WS-Trust 
(partial).</li><li><strong>Frontends:</strong> CXF supports a variety of 
"frontend" programming models.</li></ul><p>CXF implements the JAX-WS APIs. CXF 
JAX-WS support includes some extensions to the standard that make it 
significantly easier to use, compared to the reference implementation: It will 
automatically generate code for request and response bean classes, and does not 
require a WSDL for simple cases.</p><p>It also includes a "simple frontend" 
which allows creation of clients and endpoints without annotations. CXF 
supports both contract first development with WSDL and code first development 
starting from Java.</p><p>For REST, CXF also supports a JAX-RS 
frontend.</p><ul><li><strong>Ease of use:</strong> CXF is designed to be 
intuitive and easy to use. There are simple APIs to quickly build code-first 
services, Maven plug-ins to make tooling integration easy, JAX-WS API support, 
Spring
  2.x XML support to make configuration a snap, and much 
more.</li><li><strong>Binary and Legacy Protocol Support:</strong> CXF has been 
designed to provide a pluggable architecture that supports not only XML but 
also non-XML type bindings, such as JSON and CORBA, in combination with any 
type of transport.</li></ul><p>To get started using CXF, check out the <a 
shape="rect" href="download.html">downloads</a>, the <a shape="rect" 
href="http://cxf.apache.org/docs/index.html";>user's guide</a>, or the <a 
shape="rect" href="mailing-lists.html">mailing lists</a> to get more 
information!</p><h2 id="Index-Goals">Goals</h2><h3 
id="Index-General">General</h3><ul><li>High 
Performance</li><li>Extensible</li><li>Intuitive &amp; Easy to Use</li></ul><h3 
id="Index-SupportforStandards">Support for Standards</h3><h5 
id="Index-JSRSupport">JSR Support</h5><ul><li>JAX-WS - Java API for XML-Based 
Web Services (JAX-WS) 2.0 - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=224"; r
 el="nofollow">JSR-224</a></li><li>Web Services Metadata for the Java Platform 
- <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=181"; 
rel="nofollow">JSR-181</a></li><li>JAX-RS - The Java API for RESTful Web 
Services - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=311"; rel="nofollow">JSR-311,</a> <a 
shape="rect" class="external-link" href="https://jcp.org/en/jsr/detail?id=370"; 
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java 
(SAAJ) - <a shape="rect" class="external-link" 
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"; 
rel="nofollow">JSR-67</a></li></ul><h5 
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications 
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of 
Service: WS-Reliable Messaging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web 
Service Definition Language</li><li>Communication Security: WS-Security, 
WS-SecurityPolicy, WS
 -SecureConversation, WS-Trust (partial support)</li><li>Messaging Support: 
WS-Addressing, SOAP 1.1, SOAP 1.2, Message Transmission Optimization Mechanism 
(MTOM)</li></ul><h5 id="Index-OpenAPISpecification(OAS)Support">OpenAPI 
Specification (OAS) Support</h5><ul><li>OAS 2.0 (classic Swagger 
specification)</li><li>OAS 3.0.x (new revised specification)</li></ul><h3 
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple 
Transports, Protocol Bindings, Data Bindings, and 
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via 
the <a shape="rect" class="external-link" 
href="http://camel.apache.org/camel-transport-for-cxf.html";>Camel transport for 
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP, 
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans, 
Service Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON, 
FastInfoset</li><li>Extensibility API allows additional bindings for CXF, 
enablin
 g additional message format support such as CORBA/IIOP</li></ul><h3 
id="Index-FlexibleDeployment">Flexible Deployment</h3><ul><li>Lightweight 
containers: deploy services in Jetty, Tomcat or Spring-based 
containers</li><li>JBI integration: deploy as a service engine in a JBI 
container such as ServiceMix, OpenESB or Petals</li><li>Java EE integration: 
deploy services in Java EE application servers such as Apache Geronimo, JOnAS, 
Redhat JBoss, OC4J, Oracle WebLogic, and IBM WebSphere</li><li>Standalone Java 
client/server</li></ul><h3 
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple 
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server 
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way 
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS 
for RESTful clients</li><li>Support for wrapped and non-wrapped 
styles</li><li>XML messaging API</li><li>Support for JavaScript and ECMAScript 
4 XML (E4X) - bo
 th client and server</li><li>Support for CORBA</li><li>Support for JBI with 
ServiceMix</li></ul><h3 id="Index-Tooling">Tooling</h3><ul><li>Generating Code: 
WSDL to Java, WSDL to JavaScript, Java to JavaScript</li><li>Generating WSDL: 
Java to WSDL, XSD to WSDL, IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: 
WSDL to SOAP, WSDL to CORBA, WSDL to service</li><li>Generating Support Files: 
WSDL to IDL</li><li>Validating Files: WSDL Validation</li></ul><h2 
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently 
under heavy development. To get involved you can <a shape="rect" 
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab 
the code from the <a shape="rect" href="source-repository.html">Source 
Repository</a>. You also need to read about <a shape="rect" 
href="building.html">Building</a> CXF. For Eclipse users, you should read about 
<a shape="rect" href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
+<div id="ConfluenceContent"><h1 
id="Index-ApacheCXF&#8482;:AnOpen-SourceServicesFramework">Apache CXF&#8482;: 
An Open-Source Services Framework</h1><h2 
id="Index-Overview">Overview</h2><p>Apache CXF&#8482; is an open source 
services framework. CXF helps you build and develop services using frontend 
programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of 
protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a 
variety of transports such as HTTP, JMS or JBI.</p><h2 
id="Index-News">News</h2><h3 
id="Index-October8,2026-ApacheCXF4.2.4,4.1.9and3.6.13released!">October 8, 2026 
- Apache CXF 4.2.4, 4.1.9 and 3.6.13 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 9 JIRA issues were fixed for 4.2.4, 8 JIRA issues 
were fixed for 4.1.9. and&#160; 4 JIRA issues were fixed for 
3.6.13.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases
  contain fixes for multiple CVE issues, please see <a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-August5,2026-ApacheCXF4.2.3,4.1.8and3.6.12released!">August 5, 2026 - 
Apache CXF 4.2.3, 4.1.8 and 3.6.12 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 10 JIRA issues were fixed for 4.2.3, 6 JIRA issues 
were fixed for 4.1.8. and&#160; 4 JIRA issues were fixed for 
3.6.12.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for multiple 
CVE issues, please see <a shape="rect" href="security-advisories.html">Security 
Advisories</a>.</p><h3 
id="Index-June10,2026-ApacheCXF4.2.2and4.1.7released!">June 10, 2026 - Apache 
CXF 4.2.2 and 4.1.7 released!</h3><p>The Apache CXF team is proud to announce 
the availability of our latest patch releases!&#160;</p><p>Over 5 JIRA issues 
were fixed for 4.2.2 and&#160; 4 JIRA issu
 es were fixed for 4.1.7.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for multiple 
CVE issues, please see <a shape="rect" href="security-advisories.html">Security 
Advisories</a>.</p><h3 
id="Index-May20,2026-ApacheCXF4.2.1,4.1.6and3.6.11released!">May 20, 2026 - 
Apache CXF 4.2.1, 4.1.6 and 3.6.11 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 15 JIRA issues were fixed for 4.2.1, &#160;10 JIRA 
issues were fixed for 4.1.6, and 8 JIRA issues were fixed for 
3.6.11.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><p>These releases contain fixes for 3 CVE 
issues, please see&#160;<a shape="rect" 
href="security-advisories.html">Security Advisories</a>.</p><h3 
id="Index-Feb16,2026-ApacheCXF4.2.0,4.1.5,4.0.11and3.6.10released!">Feb 16, 
2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released!</h3><p>The Apache 
 CXF team is proud to announce the availability of our latest patch 
releases!&#160;</p><p>4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues 
were fixed for 4.1.5, &#160;14 JIRA issues were fixed for 4.0.11, 8 JIRA issues 
were fixed for 3.6.10.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Nov17,2025-ApacheCXF4.1.4,4.0.10and3.6.9released!">Nov 17, 2025 - 
Apache CXF 4.1.4, 4.0.10 and 3.6.9 released!</h3><p>The Apache CXF team is 
proud to announce the availability of our latest patch 
releases!&#160;</p><p>Over 13 JIRA issues were fixed for 4.1.4,&#160; 11 JIRA 
issues were fixed for 4.0.10, 12 JIRA issues were fixed for 
3.6.9.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Aug06,2025-ApacheCXF4.1.3,4.0.9and3.6.8released!">Aug 06, 2025 - 
Apache CXF 4.1.3, 4.0.9 and 3.6.8 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; 
 Over 10 JIRA issues were fixed for 4.1.3 and 4.0.9,&#160;</p><p>6 JIRA issues 
were fixed for 3.6.8. These releases contain a fix for a new CVE:</p><ul><li><a 
shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt";>https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt</a></li></ul><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-May23,2025-ApacheCXF4.1.2,4.0.8and3.6.7released!">May 23, 2025 - 
Apache CXF 4.1.2, 4.0.8 and 3.6.7 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 16 JIRA 
issues were fixed for 4.1.2,&#160;</p><p>11 JIRA issues were fixed for 4.0.8, 
10 JIRA issues were fixed for 3.6.7.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Mar6,2025-ApacheCXF4.1.1,4.0.7,3.6.6and3.5.11released!">Mar 6, 2025 - 
Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released!</h3><p>The Apache
  CXF team is proud to announce the availability of our latest patch 
releases!&#160; Over 17 JIRA issues were fixed for 4.1.1,&#160;</p><p>14 JIRA 
issues were fixed for 4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA 
issues were fixed for 3.5.11.</p><p>Please note that the CXF 3.5.11 is the last 
release of CXF 3.5.x series</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec13,2024-ApacheCXF4.1.0released!">Dec 13, 2024 - Apache CXF 4.1.0 
released!</h3><p>The Apache CXF team is proud to announce the availability of 
CXF 4.1.0! &#160;The 4.1.0 is our first release to feature Jakarta EE 10 
support and JDK-17 baseline</p><p>Over 54 JIRA issues were fixed for 
4.1.0,&#160;</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-Dec9,2024-ApacheCXF3.5.10,3.6.5and4.0.6released!">Dec 9, 2024 - 
Apache CXF 3.5.10, 3.6.5 and 4.0.6 released!</h3><p>The Apache CXF team is 
proud to announce the availab
 ility of our latest patch releases!&#160; Over 29 JIRA issues were fixed for 
4.0.6,&#160;</p><p>25 JIRA issues were fixed for 3.6.5 and 18 JIRA issues were 
fixed for 3.5.10.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-July17,2024-ApacheCXF3.5.9,3.6.4and4.0.5released!">July 17, 2024 - 
Apache CXF 3.5.9, 3.6.4 and 4.0.5 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 19 JIRA 
issues were fixed for 4.0.5.</p><p>These releases contain fixes for 3 different 
CVEs:</p><ul><li><a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt</a></li><li><a
 shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt</a></li><li><a
 shape="rect" href="https://cxf.apache.org/security-advisories
 
.data/CVE-2024-41172.txt">https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt</a></li></ul><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-March12,2024-ApacheCXF3.5.8,3.6.3and4.0.4released!">March 12, 2024 - 
Apache CXF 3.5.8, 3.6.3 and 4.0.4 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 28 JIRA 
issues were fixed for 4.0.4.</p><p>These releases contain a fix for a new 
security issue: <a shape="rect" 
href="https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt";>https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt</a></p><p>Downloads
 are available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Sept18,2023-ApacheCXF3.5.7,3.6.2and4.0.3released!">Sept 18, 2023 - 
Apache CXF 3.5.7, 3.6.2 and 4.0.3 released!</h3><p>The Apache CXF team is proud 
to announce the availability of our latest patch releases!&#160; Over 1
 5 JIRA issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are 
available&#160;<a shape="rect" href="download.html">here</a>.</p><h3 
id="Index-June12,2023-ApacheCXF3.6.1and4.0.2released!">June 12, 2023 - Apache 
CXF 3.6.1 and 4.0.2 released!</h3><p>The Apache CXF team is proud to announce 
the availability of our latest patch releases!&#160; Over 7 JIRA issues were 
fixed for 4.0.2 and 3.6.1.</p><p>Downloads are available&#160;<a shape="rect" 
href="download.html">here</a>.</p><h3 
id="Index-May8,2023-ApacheCXF3.5.6,3.6.0and4.0.1released!">May 8, 2023 - Apache 
CXF 3.5.6, 3.6.0 and 4.0.1 released!</h3><p>The Apache CXF team is proud to 
announce the availability of our latest patch releases!&#160; Over 15 JIRA 
issues were fixed for 4.01 and 3.5.6.</p><p>Downloads are available&#160;<a 
shape="rect" href="download.html">here</a>.</p><h3 
id="Index-Features">Features</h3><p>CXF includes a broad feature set, but it is 
primarily focused on the following areas:</p><ul><li><strong>Web Services St
 andards Support:</strong> CXF supports a variety of web service standards 
including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy, 
WS-ReliableMessaging, WS-Security, WS-SecurityPolicy, WS-SecureConverstation, 
and WS-Trust (partial).</li><li><strong>Frontends:</strong> CXF supports a 
variety of "frontend" programming models.</li></ul><p>CXF implements the JAX-WS 
APIs. CXF JAX-WS support includes some extensions to the standard that make it 
significantly easier to use, compared to the reference implementation: It will 
automatically generate code for request and response bean classes, and does not 
require a WSDL for simple cases.</p><p>It also includes a "simple frontend" 
which allows creation of clients and endpoints without annotations. CXF 
supports both contract first development with WSDL and code first development 
starting from Java.</p><p>For REST, CXF also supports a JAX-RS 
frontend.</p><ul><li><strong>Ease of use:</strong> CXF is designed to be 
intuitive and easy
  to use. There are simple APIs to quickly build code-first services, Maven 
plug-ins to make tooling integration easy, JAX-WS API support, Spring 2.x XML 
support to make configuration a snap, and much more.</li><li><strong>Binary and 
Legacy Protocol Support:</strong> CXF has been designed to provide a pluggable 
architecture that supports not only XML but also non-XML type bindings, such as 
JSON and CORBA, in combination with any type of transport.</li></ul><p>To get 
started using CXF, check out the <a shape="rect" 
href="download.html">downloads</a>, the <a shape="rect" 
href="http://cxf.apache.org/docs/index.html";>user's guide</a>, or the <a 
shape="rect" href="mailing-lists.html">mailing lists</a> to get more 
information!</p><h2 id="Index-Goals">Goals</h2><h3 
id="Index-General">General</h3><ul><li>High 
Performance</li><li>Extensible</li><li>Intuitive &amp; Easy to Use</li></ul><h3 
id="Index-SupportforStandards">Support for Standards</h3><h5 
id="Index-JSRSupport">JSR Support</h5><ul><l
 i>JAX-WS - Java API for XML-Based Web Services (JAX-WS) 2.0 - <a shape="rect" 
class="external-link" href="http://jcp.org/en/jsr/detail?id=224"; 
rel="nofollow">JSR-224</a></li><li>Web Services Metadata for the Java Platform 
- <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=181"; 
rel="nofollow">JSR-181</a></li><li>JAX-RS - The Java API for RESTful Web 
Services - <a shape="rect" class="external-link" 
href="http://jcp.org/en/jsr/detail?id=311"; rel="nofollow">JSR-311,</a> <a 
shape="rect" class="external-link" href="https://jcp.org/en/jsr/detail?id=370"; 
rel="nofollow">JSR-370</a></li><li>SAAJ - SOAP with Attachments API for Java 
(SAAJ) - <a shape="rect" class="external-link" 
href="http://jcp.org/aboutJava/communityprocess/mrel/jsr067/index3.html"; 
rel="nofollow">JSR-67</a></li></ul><h5 
id="Index-WS-*andrelatedSpecificationsSupport">WS-* and related Specifications 
Support</h5><ul><li>Basic support: WS-I Basic Profile 1.1</li><li>Quality of 
Service: WS-Reliable Mess
 aging</li><li>Metadata: WS-Policy, WSDL 1.1 - Web Service Definition 
Language</li><li>Communication Security: WS-Security, WS-SecurityPolicy, 
WS-SecureConversation, WS-Trust (partial support)</li><li>Messaging Support: 
WS-Addressing, SOAP 1.1, SOAP 1.2, Message Transmission Optimization Mechanism 
(MTOM)</li></ul><h5 id="Index-OpenAPISpecification(OAS)Support">OpenAPI 
Specification (OAS) Support</h5><ul><li>OAS 2.0 (classic Swagger 
specification)</li><li>OAS 3.0.x (new revised specification)</li></ul><h3 
id="Index-MultipleTransports,ProtocolBindings,DataBindings,andFormats">Multiple 
Transports, Protocol Bindings, Data Bindings, and 
Formats</h3><ul><li>Transports: HTTP, Servlet, JMS, In-VM and many others via 
the <a shape="rect" class="external-link" 
href="http://camel.apache.org/camel-transport-for-cxf.html";>Camel transport for 
CXF</a> such as SMTP/POP3, TCP and Jabber</li><li>Protocol Bindings: SOAP, 
REST/HTTP, pure XML</li><li>Data bindings: JAXB 2.x, Aegis, Apache XMLBeans, 
Servic
 e Data Objects (SDO), JiBX</li><li>Formats: XML Textual, JSON, 
FastInfoset</li><li>Extensibility API allows additional bindings for CXF, 
enabling additional message format support such as CORBA/IIOP</li></ul><h3 
id="Index-FlexibleDeployment">Flexible Deployment</h3><ul><li>Lightweight 
containers: deploy services in Jetty, Tomcat or Spring-based 
containers</li><li>JBI integration: deploy as a service engine in a JBI 
container such as ServiceMix, OpenESB or Petals</li><li>Java EE integration: 
deploy services in Java EE application servers such as Apache Geronimo, JOnAS, 
Redhat JBoss, OC4J, Oracle WebLogic, and IBM WebSphere</li><li>Standalone Java 
client/server</li></ul><h3 
id="Index-SupportforMultipleProgrammingLanguages">Support for Multiple 
Programming Languages</h3><ul><li>Full support for JAX-WS 2.x client/server 
programming model</li><li>JAX-WS 2.x synchronous, asynchronous and one-way 
API's</li><li>JAX-WS 2.x Dynamic Invocation Interface (DII) API</li><li>JAX-RS 
for RESTful cli
 ents</li><li>Support for wrapped and non-wrapped styles</li><li>XML messaging 
API</li><li>Support for JavaScript and ECMAScript 4 XML (E4X) - both client and 
server</li><li>Support for CORBA</li><li>Support for JBI with 
ServiceMix</li></ul><h3 id="Index-Tooling">Tooling</h3><ul><li>Generating Code: 
WSDL to Java, WSDL to JavaScript, Java to JavaScript</li><li>Generating WSDL: 
Java to WSDL, XSD to WSDL, IDL to WSDL, WSDL to XML</li><li>Adding Endpoints: 
WSDL to SOAP, WSDL to CORBA, WSDL to service</li><li>Generating Support Files: 
WSDL to IDL</li><li>Validating Files: WSDL Validation</li></ul><h2 
id="Index-GettingInvolved">Getting Involved</h2><p>Apache CXF is currently 
under heavy development. To get involved you can <a shape="rect" 
href="mailing-lists.html">subscribe to the mailing lists</a>. You can also grab 
the code from the <a shape="rect" href="source-repository.html">Source 
Repository</a>. You also need to read about <a shape="rect" 
href="building.html">Building</a> CXF. For E
 clipse users, you should read about <a shape="rect" 
href="setting-up-eclipse.html">Setting up Eclipse</a>.</p></div>
            </div>
            <!-- Content -->
          </td>

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-100227.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ 
websites/production/cxf/content/security-advisories.data/CVE-2026-100227.txt    
    Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,23 @@
+CVE-2026-100227: Apache CXF: XML Signature wrapping in JAX-RS XML Security 
+
+Severity: moderate 
+
+Affected versions:
+
+- Apache CXF 4.2.0 before 4.2.4
+- Apache CXF 4.0.0 before 4.1.9
+- Apache CXF before 3.6.13
+
+Description:
+
+Improper Verification of Cryptographic Signature vulnerability in Apache CXF's 
JAX-RS XML Security module. The JAX-RS XML Signature interceptors 
(XmlSigInHandler, XmlSigInInterceptor and the streaming XmlSecInInterceptor) 
did not ensure that the XML passed to the application was covered by the 
signature. An attacker with any document signed by a trusted key could wrap it 
in unsigned content, which the application would then treat as signed.
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+This issue was found using Claude agents to study the security of open-source 
projects and independently by Guanping Zhang (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-100227

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-107937.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ 
websites/production/cxf/content/security-advisories.data/CVE-2026-107937.txt    
    Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,23 @@
+CVE-2026-107937: Apache CXF: The attachment header size and count limits can 
be bypassed, which allows denial of service through memory exhaustion. 
+
+Severity: low 
+
+Affected versions:
+
+- Apache CXF 4.2.0 before 4.2.4
+- Apache CXF 4.0.0 before 4.1.9
+- Apache CXF before 3.6.13
+
+Description:
+
+In Apache CXF, the parser for multipart/MTOM attachment part headers did not 
fully enforce the configured attachment-max-header-size (default 300 
characters) and attachment-headers-max-count (default 500) limits. The size 
limit was applied only to each physical line, not to a header value built from 
continuation lines or to the combined values of a repeated header. The count 
limit was checked against the number of distinct header names, not the total 
number of header lines. A remote, unauthenticated attacker could send a 
multipart request with very large folded or repeated part headers. The server 
would then allocate memory without bound, causing a denial of service. 
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+This issue was found using Claude agents to study the security of open-source 
projects and independently by Mike Read (github.com/Michael-JRead) (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-107937

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-107938.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ 
websites/production/cxf/content/security-advisories.data/CVE-2026-107938.txt    
    Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,23 @@
+CVE-2026-107938: Apache CXF: The Netty HTTP client transport does not perform 
TLS hostname verification. 
+
+Severity: important 
+
+Affected versions:
+
+- Apache CXF 4.2.0 before 4.2.4
+- Apache CXF 4.0.0 before 4.1.9
+- Apache CXF before 3.6.13
+
+Description:
+
+In Apache CXF, the Netty-based HTTP client transport 
(cxf-rt-transports-http-netty-client) did not verify that the hostname in the 
server’s TLS certificate matched the host being called. This applied over both 
HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of 
false. The certificate chain was validated against the configured trust store, 
but the endpoint’s identity was not. A network attacker able to intercept 
traffic could present any certificate trusted by the client, such as a publicly 
issued certificate for a domain they control, and impersonate the target 
service. They could then read or modify the exchanged messages, including 
credentials. 
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+This issue was found using Claude agents to study the security of open-source 
projects (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-107938

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-108039.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ 
websites/production/cxf/content/security-advisories.data/CVE-2026-108039.txt    
    Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,23 @@
+CVE-2026-108039: Apache CXF: Prevent unbounded XML document size in StaxUtils 
by adding default element and character limits 
+
+Severity: low 
+
+Affected versions:
+
+- Apache CXF 4.2.0 before 4.2.4
+- Apache CXF 4.0.0 before 4.1.9
+- Apache CXF before 3.6.13
+
+Description:
+
+By default, StaxUtils placed no limit on the total number of elements or the 
total number of characters in an XML document. A very large request could 
therefore use a lot of memory and CPU during parsing, especially where CXF 
builds a DOM from the input (for example SAAJ or WS-Security), and could cause 
a denial of service when no request size limit was configured. Both limits now 
have defaults: the maximum element count is 100 × maxChildElements (5,000,000 
by default), and the maximum document size is 256M characters. Applications 
that process larger documents can raise the limits with the 
org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters 
properties.
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+Wanxin Yin (yaklang.io) <[email protected]> (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-108039

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-79650.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-79650.txt 
Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,22 @@
+CVE-2026-79650: Apache CXF: OIDC RP Open Redirect 
+
+Severity: important 
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-sso-oidc) 4.2.0 before 4.2.4
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-sso-oidc) 4.0.0 before 4.1.9
+- Apache CXF (org.apache.cxf:cxf-rt-rs-security-sso-oidc) before 3.6.13
+
+Description:
+
+Apache CXF’s OIDC relying-party component could redirect users to an 
attacker-controlled URL after successful authentication. The issue occurs 
because attacker-controlled state parameters are preserved and later used as 
redirect targets without validating that the final decoded URI belongs to the 
RP’s origin. Both directly encoded and double-encoded external URLs can trigger 
the issue, depending on which validation path is used. Users are recommended to 
upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
+
+Credit:
+
+Guanping Zhang reported this vulnerability (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-79650

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-86463.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-86463.txt 
Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,25 @@
+CVE-2026-86463: Apache CXF: FIQL Query Parser Denial of Service 
+
+Severity: low 
+
+Affected versions:
+
+- Apache CXF (org.apache.cxf:cxf-rt-rs-extension-search) 4.2.0 before 4.2.4
+- Apache CXF (org.apache.cxf:cxf-rt-rs-extension-search) 4.0.0 before 4.1.9
+- Apache CXF (org.apache.cxf:cxf-rt-rs-extension-search) before 3.6.13
+
+Description:
+
+Apache CXF's FIQL query parser has a vulnerability in how it searches for 
operators in query expressions. The search pattern can get stuck trying many 
combinations when it encounters a long string without an operator, causing the 
parser to consume excessive CPU time. An attacker can send a crafted query to 
make the server use up CPU resources, potentially slowing down or stopping 
other requests. The fix was to limit FIQL expressions to 4 KiB by default, 
preventing attackers from sending extremely long inputs while still allowing 
normal queries.
+
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+Mike Read (github.com/Michael-JRead) (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-86463
+

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-97468.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-97468.txt 
Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,24 @@
+CVE-2026-97468: Apache CXF: Authentication bypass via weak cache keys for 
validated STS tokens 
+
+Severity: important 
+
+Affected versions:
+
+- Apache CXF 4.2.0 before 4.2.4
+- Apache CXF 4.0.0 before 4.1.9
+- Apache CXF before 3.6.13
+
+Description:
+
+Apache CXF's STSTokenValidator and Security Token Service (STS) cached 
validated security tokens under a non-cryptographic 32-bit hash of the token 
(Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the 
presented token had already been validated. An attacker could craft a token 
(for example a UsernameToken or a self-signed SAML Assertion) whose hash 
collides with a cached entry. The token would then be accepted without password 
validation, signature trust verification or a call to the STS. This could let 
the attacker authenticate as another user and, through STS token validation or 
renewal, obtain STS-signed tokens for that identity.
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+MopMonk-AI (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-97468
+

Added: 
websites/production/cxf/content/security-advisories.data/CVE-2026-97791.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ websites/production/cxf/content/security-advisories.data/CVE-2026-97791.txt 
Fri Oct  9 09:43:18 2026        (r1094223)
@@ -0,0 +1,24 @@
+CVE-2026-97791: Apache CXF: STSTokenValidator can accept untrusted SAML 
assertions because it shares validation state between requests 
+
+Severity: important 
+
+Affected versions:
+
+- Apache CXF 4.2.0 before 4.2.4
+- Apache CXF 4.0.0 before 4.1.9
+- Apache CXF before 3.6.13
+
+Description:
+
+In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by 
a trusted certificate before deciding to send it to the STS. That result was 
stored in one object shared by all requests, so one request could read 
another's result. A remote, unauthenticated attacker could send a forged 
assertion signed with an untrusted certificate while legitimate requests were 
being processed, and it could be accepted as trusted without ever reaching the 
STS. Only services that use STSTokenValidator to validate SAML tokens without 
alwaysValidateToSts set are affected. 
+Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.
+
+Credit:
+
+MopMonk-AI (finder)
+
+References:
+
+https://cxf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-97791
+

Modified: websites/production/cxf/content/security-advisories.html
==============================================================================
--- websites/production/cxf/content/security-advisories.html    Fri Oct  9 
09:04:47 2026        (r1094222)
+++ websites/production/cxf/content/security-advisories.html    Fri Oct  9 
09:43:18 2026        (r1094223)
@@ -99,7 +99,7 @@ Apache CXF -- Security Advisories
          <td height="100%">
            <!-- Content -->
            <div class="wiki-content">
-<div id="ConfluenceContent"><p><span style="color:var(--ds-text,#333333);">For 
information on how to report a new security problem please 
see<span>&#160;</span></span><a shape="rect" class="external-link" 
href="https://www.apache.org/security/"; style="text-decoration: 
none;">here</a><span 
style="color:var(--ds-text,#333333);">.<span>&#160;</span></span></p><h3 
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44417.txt?version=1&amp;modificationDate=1779445819000&amp;api=v2"
 data-linked-resource-id="429064531" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-44417</a>: Apache CXF: 
Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to 
RCE)</li><li><a shape="rect" hr
 
ef="security-advisories.data/CVE-2026-44618.txt?version=1&amp;modificationDate=1779445877000&amp;api=v2"
 data-linked-resource-id="429064532" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-44618</a>: Apache CXF: XXE 
vulnerability in WS-Transfer functionality</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44930.txt?version=1&amp;modificationDate=1779445722000&amp;api=v2"
 data-linked-resource-id="429064529" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-44930</a>: Apache C
 XF: LDAP Injection vulnerability in XKMS LDAP Repository</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-49875.txt?version=3&amp;modificationDate=1786100539000&amp;api=v2"
 data-linked-resource-id="430408836" data-linked-resource-version="3" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-49875</a>: Apache CXF: XML 
External Entity (XXE) Injection in W3CMultiSchemaFactory and 
EndpointReferenceUtils&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50623.txt?version=2&amp;modificationDate=1786100738000&amp;api=v2"
 data-linked-resource-id="430408838" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text 
File" data-linked-resource-content-type=
 "text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50623</a>: Apache CXF: 
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50627.txt?version=2&amp;modificationDate=1786100822000&amp;api=v2"
 data-linked-resource-id="430408839" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50627</a>: Apache CXF: 
OAuth2: Missing JWT Audience and Issuer Validation in Access Token 
Validator</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50628.txt?version=2&amp;modificationDate=1786100892000&amp;api=v2"
 data-linked-resource-id="430408840" data-linked-resource-version="2" 
data-linked-resource-type="attachment"
  data-linked-resource-default-alias="CVE-2026-50628.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50628</a>: Apache CXF: 
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50629.txt?version=2&amp;modificationDate=1786101020000&amp;api=v2"
 data-linked-resource-id="430408842" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50629</a>: Apache CXF: 
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50630.txt?version=2&amp;modificationDate=1786101091000&amp;api=v2"
 data-link
 ed-resource-id="430408843" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50630</a>: Apache CXF: 
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm 
Injection&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50631.txt?version=2&amp;modificationDate=1786101161000&amp;api=v2"
 data-linked-resource-id="430408844" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50631</a>: Apache CXF: 
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a 
shape="rect" 
 
href="security-advisories.data/CVE-2026-50632.txt?version=3&amp;modificationDate=1786101236000&amp;api=v2"
 data-linked-resource-id="430408845" data-linked-resource-version="3" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50632.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50632:</a> Apache CXF: 
JNDI Injection Vulnerability in JMSConfigFactory</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50633.txt?version=2&amp;modificationDate=1786101322000&amp;api=v2"
 data-linked-resource-id="430408847" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50633</a>: Apac
 he CXF: JNDI Injection vulnerability in 
DispatchMDBMessageListenerImpl</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50634.txt?version=2&amp;modificationDate=1786101412000&amp;api=v2"
 data-linked-resource-id="430408848" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50634.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50634</a>: Apache CXF: WS 
JSON request filter trusts metadata from an unvalidated first signature 
entry</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50645.txt?version=4&amp;modificationDate=1786101529000&amp;api=v2"
 data-linked-resource-id="430408849" data-linked-resource-version="4" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50645.txt" data-nice-type="Text 
File" data-linked-resource-content-type
 ="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-50645</a>: Apache CXF: No 
restriction on attachment headers per message</li><li 
data-uuid="49670750-d78a-4fe2-a830-cc372623486a"><a shape="rect" 
href="security-advisories.data/CVE-2026-54225.txt?version=1&amp;modificationDate=1786010395000&amp;api=v2"
 data-linked-resource-id="446071159" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-54225.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-54225</a>: Apache CXF: 
Denial of Service attack via large attachments</li><li 
data-uuid="4d3b7d2a-2f95-4a2a-a0a4-16f3020d96a7"><a shape="rect" 
href="security-advisories.data/CVE-2026-57817.txt?version=1&amp;modificationDate=1786011692000&amp;api=v2"
 data-linked-resource-id="446071172" data-linked
 -resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-57817.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-57817</a>: Apache CXF: The 
authorization code hash (c_hash) is not enforced for the hybrid OIDC 
flow</li><li data-uuid="421dab32-bb7b-4d04-a713-bf4012dab629"><a shape="rect" 
href="security-advisories.data/CVE-2026-57818.txt?version=1&amp;modificationDate=1786011946000&amp;api=v2"
 data-linked-resource-id="446071174" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-57818.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-57818</a>: Apache CXF: 
OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvide
 r</li><li data-uuid="9d893f5b-4577-4891-9f8a-c2a20c2a5a4d"><a shape="rect" 
href="security-advisories.data/CVE-2026-57819.txt?version=1&amp;modificationDate=1786010722000&amp;api=v2"
 data-linked-resource-id="446071161" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-57819.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-57819</a>: Apache CXF: No 
default restriction on the amount of form parameters per message</li><li 
data-uuid="37f9ccab-4420-47c2-9438-12b46f6066e1"><a shape="rect" 
href="security-advisories.data/CVE-2026-61466.txt?version=1&amp;modificationDate=1786012193000&amp;api=v2"
 data-linked-resource-id="446071176" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-61466.txt" data-nice-type="Text 
File" data-linked-resou
 rce-content-type="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-61466</a>: Apache CXF: 
OAuth2 Dynamic Client Registration Scope Self-Escalation</li><li 
data-uuid="7c0ccedd-3bf8-4f26-993b-1ee8e96c74a4"><a shape="rect" 
href="security-advisories.data/CVE-2026-63687.txt?version=2&amp;modificationDate=1786012916000&amp;api=v2"
 data-linked-resource-id="446071178" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-63687.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-63687</a>: Apache CXF: 
JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters</li><li 
data-uuid="497c4f06-b436-4629-aa2d-e022a5268c29"><a shape="rect" 
href="security-advisories.data/CVE-2026-64958.txt?version=1&amp;modificationDate=1786011007000&amp;api=v2
 " data-linked-resource-id="446071164" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-64958.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-64958</a>: Apache CXF: 
Denial of service via message header attachments</li><li 
data-uuid="b0b1eaaa-380b-4004-acbf-c135ef8b97e1"><a shape="rect" 
href="security-advisories.data/CVE-2026-65432.txt?version=1&amp;modificationDate=1786011271000&amp;api=v2"
 data-linked-resource-id="446071166" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-65432.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-65432</a>: Apache CXF: XXE 
via WSDL/XSD import parsing</li><li data-uui
 d="7f19a0df-3457-45ef-bd8f-cfe71b66943c"><a shape="rect" 
href="security-advisories.data/CVE-2026-65583.txt?version=1&amp;modificationDate=1786013097000&amp;api=v2"
 data-linked-resource-id="446071184" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-65583.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-65583</a>: Apache CXF: 
Self-issued ID token claims validation skipped</li><li 
data-uuid="2693b482-0db3-4743-aa55-aec24d4be213"><a shape="rect" 
href="security-advisories.data/CVE-2026-66909.txt?version=2&amp;modificationDate=1786011477000&amp;api=v2"
 data-linked-resource-id="446071168" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-66909.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" data-link
 ed-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-66909</a>: Apache CXF: 
Unsafe deserialization of inbound JMS ObjectMessage</li><li 
data-uuid="89ccf4e0-27b8-46a2-b30b-c382bf070593"><a shape="rect" 
href="security-advisories.data/CVE-2026-68079.txt?version=1&amp;modificationDate=1786013245000&amp;api=v2"
 data-linked-resource-id="446071186" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-68079.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-68079</a>: Apache CXF: 
DefaultEncryptingCodeDataProvider allows unlimited authorization code 
replay</li><li data-uuid="ab47b81c-be3b-460d-acdb-cb9a11f85d57"><a shape="rect" 
href="security-advisories.data/CVE-2026-68481.txt?version=3&amp;modificationDate=1786013432000&amp;api=v2"
 data-linked-resource-id="446071188" d
 ata-linked-resource-version="3" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-68481.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-68481</a>: Apache CXF: 
Revocation bypass in DefaultEncryptingOAuthDataProvider</li><li 
data-uuid="12d301a8-d0e6-4e39-8b16-fd1b95516d5b"><a shape="rect" 
href="security-advisories.data/CVE-2026-50645.txt?version=4&amp;modificationDate=1786101529000&amp;api=v2"
 data-linked-resource-id="430408849" data-linked-resource-version="4" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50645.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-71575</a>: Apache CXF: 
Inoperative max_age authentication-freshness check in OidcClientCodeRequestFilte
 r</li><li data-uuid="c650d80c-48b7-402b-8b92-bd571b7d8a0f"><a shape="rect" 
href="security-advisories.data/CVE-2026-73179.txt?version=1&amp;modificationDate=1791535144439&amp;api=v2"
 data-linked-resource-id="451979420" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-73179.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-73179</a>: Apache CXF: JPA 
authorization-code consume is non-atomic</li><li 
data-uuid="17b33361-b798-4722-a7f6-2fd7586cc513"><a shape="rect" 
href="security-advisories.data/CVE-2026-73179.txt?version=1&amp;modificationDate=1791535144439&amp;api=v2"
 data-linked-resource-id="451979420" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-73179.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/
 plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2026-78384</a>: Apache CXF: 
Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing 
(Decompression Bomb)</li></ul><h3 
id="SecurityAdvisories-2025">2025</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2025-23184.txt?version=2&amp;modificationDate=1737381863000&amp;api=v2"
 data-linked-resource-id="340036025" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2025-23184</a>: Apache CXF: 
Denial of Service vulnerability with temporary files&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48795.txt?version=1&amp;modificationDate=1752578416000&amp;api=v2"
 data-linked-resource-id="373886120" data-linked-r
 esource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-48795.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2025-48795</a>: Apache CXF: 
Denial of Service and sensitive data exposure in logs&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48913.txt?version=1&amp;modificationDate=1754576095000&amp;api=v2"
 data-linked-resource-id="373887565" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2025-48913</a>: Apache CXF: 
Untrusted JMS configuration can lead to RCE&#160;</li></ul><h3 
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect" href="securi
 
ty-advisories.data/CVE-2024-28752.txt?version=2&amp;modificationDate=1710431346000&amp;api=v2"
 data-linked-resource-id="296290905" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2024-28752</a>: Apache CXF SSRF 
Vulnerability using the Aegis databinding&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-29736.txt?version=1&amp;modificationDate=1721314668000&amp;api=v2"
 data-linked-resource-id="315493016" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2024-29736</a>: SSRF vulnerab
 ility via WADL stylesheet parameter</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-32007.txt?version=1&amp;modificationDate=1721314761000&amp;api=v2"
 data-linked-resource-id="315493017" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2024-32007</a>: Apache CXF 
Denial of Service vulnerability in JOSE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-41172.txt?version=1&amp;modificationDate=1721314821000&amp;api=v2"
 data-linked-resource-id="315493018" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-linked-resour
 ce-container-version="97">CVE-2024-41172</a>: Unrestricted memory consumption 
in CXF HTTP clients</li></ul><h3 
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46363.txt?version=1&amp;modificationDate=1670942001000&amp;api=v2"
 data-linked-resource-id="235836918" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2022-46363</a>: Apache CXF 
directory listing / code exfiltration</li><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46364.txt?version=1&amp;modificationDate=1670944473000&amp;api=v2"
 data-linked-resource-id="235836926" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text 
File"
  data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2022-46364</a>: Apache CXF SSRF 
Vulnerability</li></ul><h3 id="SecurityAdvisories-2021">2021</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&amp;modificationDate=1623835370000&amp;api=v2"
 data-linked-resource-id="181310680" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2021-30468.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2021-30468</a>: Apache CXF 
Denial of service vulnerability in parsing JSON via 
JsonMapObjectReaderWriter</li><li><a shape="rect" 
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&amp;modificationDate=1617355743000&amp;api=v2"
 data-linked-resource-id="177049091" data-linked-r
 esource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2021-22696.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2021-22696</a>: OAuth 2 
authorization service vulnerable to DDos attacks</li></ul><h3 
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&amp;modificationDate=1605183671000&amp;api=v2"
 data-linked-resource-id="165225095" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-13954.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2020-13954</a>: Apache CXF 
Reflected XSS in the services listing page via the styleSheetPath</li><li><a 
shape="rect" 
 
href="security-advisories.data/CVE-2020-1954.txt.asc?version=1&amp;modificationDate=1585730169000&amp;api=v2"
 data-linked-resource-id="148645097" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2020-1954</a>: Apache CXF JMX 
Integration is vulnerable to a MITM attack</li></ul><h3 
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&amp;modificationDate=1584610519000&amp;api=v2"
 data-linked-resource-id="145722246" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-17573.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-li
 nked-resource-container-version="97">CVE-2019-17573</a>: Apache CXF Reflected 
XSS in the services listing page</li><li><a shape="rect" 
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&amp;modificationDate=1579178393000&amp;api=v2"
 data-linked-resource-id="145722244" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12423.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2019-12423</a>: Apache CXF 
OpenId Connect JWK Keys service returns private/secret credentials if 
configured with a jwk keystore</li><li><a shape="rect" 
href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&amp;modificationDate=1572961201000&amp;api=v2"
 data-linked-resource-id="135859612" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-
 12419.txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2019-12419</a>: Apache CXF 
OpenId Connect token service does not properly validate the clientId</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&amp;modificationDate=1572957147000&amp;api=v2"
 data-linked-resource-id="135859607" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12406.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2019-12406</a>: Apache CXF does 
not restrict the number of message attachments</li></ul><h3 
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&amp;modificationDate=15301846630
 00&amp;api=v2" data-linked-resource-id="87296645" 
data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2018-8039</a>: Apache CXF TLS 
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&amp;modificationDate=1530712328000&amp;api=v2"
 data-linked-resource-id="87297524" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8038.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2018-8038</a>: Apache CXF Fediz 
is vulnerable to DTD based XML attacks</li></ul><h3 
 id="SecurityAdvisories-2017">2017</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&amp;modificationDate=1512037276000&amp;api=v2"
 data-linked-resource-id="74688816" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12631.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2017-12631</a>: CSRF 
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&amp;modificationDate=1510661632000&amp;api=v2"
 data-linked-resource-id="74687100" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12624.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27
 837502" data-linked-resource-container-version="97">CVE-2017-12624</a>: Apache 
CXF web services that process attachments are vulnerable to Denial of Service 
(DoS) attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&amp;modificationDate=1494949377000&amp;api=v2"
 data-linked-resource-id="70255583" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2017-7662</a>: The Apache CXF 
Fediz OIDC Client Registration Service is vulnerable to CSRF 
attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&amp;modificationDate=1494949364000&amp;api=v2"
 data-linked-resource-id="70255582" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-resou
 rce-default-alias="CVE-2017-7661.txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2017-7661</a>: The Apache CXF 
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&amp;modificationDate=1492515113000&amp;api=v2"
 data-linked-resource-id="69406543" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2017-5656</a>: Apache CXF's 
STSClient uses a flawed way of caching tokens that are associated with 
delegation tokens.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&amp;modificationDate=14
 92515074000&amp;api=v2" data-linked-resource-id="69406542" 
data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2017-5653</a>: Apache CXF 
JAX-RS XML Security streaming clients do not validate that the service response 
was signed or encrypted.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&amp;modificationDate=1487590374000&amp;api=v2"
 data-linked-resource-id="68715428" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-3156.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2017-3156</a>: Apache CXF 
OAuth2 Hawk and 
 JOSE MAC Validation code is vulnerable to the timing attacks</li></ul><h3 
id="SecurityAdvisories-2016">2016</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635454" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2016-8739</a>: Atom entity 
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-6812.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635455" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text 
File" data-linked-r
 esource-content-type="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2016-6812</a>: XSS risk in 
Apache CXF FormattedServiceListWriter when a request URL contains matrix 
parameters</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&amp;modificationDate=1473350153000&amp;api=v2"
 data-linked-resource-id="65869472" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2016-4464</a>: Apache CXF Fediz 
application plugins do not match the SAML AudienceRestriction values against 
the list of configured audience URIs</li></ul><h3 
id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&amp;modi
 ficationDate=1447433340000&amp;api=v2" data-linked-resource-id="61328642" 
data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2015-5253</a>: Apache CXF SAML 
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&amp;modificationDate=1440598018000&amp;api=v2"
 data-linked-resource-id="61316328" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5175.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2015-5175</a>: Apache CXF Fediz 
application plugins are vulnerable to Denial 
 of Service (DoS) attacks</li></ul><h3 
id="SecurityAdvisories-2014">2014</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&amp;modificationDate=1419245371000&amp;api=v2"
 data-linked-resource-id="51183657" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-3577</a>: Apache CXF SSL 
hostname verification bypass</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&amp;modificationDate=1418740474000&amp;api=v2"
 data-linked-resource-id="50561078" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" data-linked-resource-
 container-id="27837502" data-linked-resource-container-version="97">Note on 
CVE-2014-3566</a>: SSL 3.0 support in Apache CXF, aka the "POODLE" 
attack.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&amp;modificationDate=1414169368000&amp;api=v2"
 data-linked-resource-id="47743195" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-3623</a>: Apache CXF does 
not properly enforce the security semantics of SAML SubjectConfirmation methods 
when used with the TransportBinding</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&amp;modificationDate=1414169326000&amp;api=v2"
 data-linked-resource-id="47743194" data-linked-resource-version="1" 
data-linked-resource-type="att
 achment" data-linked-resource-default-alias="CVE-2014-3584.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-3584</a>: Apache CXF 
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS) 
attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&amp;modificationDate=1398873370000&amp;api=v2"
 data-linked-resource-id="40895138" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-0109</a>: HTML content 
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&amp;modificationDate=1398873378000&a
 mp;api=v2" data-linked-resource-id="40895139" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-0110</a>: Large invalid 
content could cause temporary space to fill</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&amp;modificationDate=1398873385000&amp;api=v2"
 data-linked-resource-id="40895140" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0034.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-0034</a>: The 
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a 
shape="rect" href
 
="security-advisories.data/CVE-2014-0035.txt.asc?version=1&amp;modificationDate=1398873391000&amp;api=v2"
 data-linked-resource-id="40895141" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="97">CVE-2014-0035</a>: UsernameTokens 
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3 
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&amp;modificationDate=1372324301000&amp;api=v2"
 data-linked-resource-id="33095710" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="2
 7837502" data-linked-resource-container-version="97">CVE-2013-2160</a> - 
Denial of Service Attacks on Apache CXF</li><li><a shape="rect" 
href="cve-2012-5575.html">Note on CVE-2012-5575</a> - XML Encryption backwards 
compatibility attack on Apache CXF.</li><li><a shape="rect" 
href="cve-2013-0239.html">CVE-2013-0239</a> - Authentication bypass in the case 
of WS-SecurityPolicy enabled plaintext UsernameTokens.</li></ul><h3 
id="SecurityAdvisories-2012">2012</h3><ul><li><a shape="rect" 
href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor always allows 
HTTP Get requests from browser.</li><li><a shape="rect" 
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher 
attack against distributed symmetric key in WS-Security.</li><li><a 
shape="rect" href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is 
vulnerable to SOAP Action spoofing attacks on Document Literal web 
services.</li><li><a shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> - 
Apache CXF 
 does not verify that elements were signed or encrypted by a particular 
Supporting Token.</li><li><a shape="rect" 
href="cve-2012-2378.html">CVE-2012-2378</a> - Apache CXF does not pick up some 
child policies of WS-SecurityPolicy 1.1 SupportingToken policy assertions on 
the client side.</li><li><a shape="rect" href="note-on-cve-2011-1096.html">Note 
on CVE-2011-1096</a> - XML Encryption flaw / Character pattern encoding 
attack.</li><li><a shape="rect" href="cve-2012-0803.html">CVE-2012-0803</a> - 
Apache CXF does not validate UsernameToken policies correctly.</li></ul><h3 
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf";>CVE-2010-2076</a>
 - DTD based XML attacks.</li></ul><p><br clear="none"></p></div>
+<div id="ConfluenceContent"><p><span style="color:var(--ds-text,#333333);">For 
information on how to report a new security problem please 
see<span>&#160;</span></span><a shape="rect" class="external-link" 
href="https://www.apache.org/security/"; style="text-decoration: 
none;">here</a><span 
style="color:var(--ds-text,#333333);">.<span>&#160;</span></span></p><h3 
id="SecurityAdvisories-2026">2026</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44417.txt?version=1&amp;modificationDate=1779445819000&amp;api=v2"
 data-linked-resource-id="429064531" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44417.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-44417</a>: Apache CXF: 
Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to 
RCE)</li><li><a shape="rect" h
 
ref="security-advisories.data/CVE-2026-44618.txt?version=1&amp;modificationDate=1779445877000&amp;api=v2"
 data-linked-resource-id="429064532" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44618.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-44618</a>: Apache CXF: 
XXE vulnerability in WS-Transfer functionality</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-44930.txt?version=1&amp;modificationDate=1779445722000&amp;api=v2"
 data-linked-resource-id="429064529" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-44930.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-44930</a>: Apach
 e CXF: LDAP Injection vulnerability in XKMS LDAP Repository</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-49875.txt?version=3&amp;modificationDate=1786100539000&amp;api=v2"
 data-linked-resource-id="430408836" data-linked-resource-version="3" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-49875.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-49875</a>: Apache CXF: 
XML External Entity (XXE) Injection in W3CMultiSchemaFactory and 
EndpointReferenceUtils&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50623.txt?version=2&amp;modificationDate=1786100738000&amp;api=v2"
 data-linked-resource-id="430408838" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50623.txt" data-nice-type="Text 
File" data-linked-resource-content-t
 ype="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50623</a>: Apache CXF: 
Authentication Bypass in OAuth2 TokenIntrospectionService</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50627.txt?version=2&amp;modificationDate=1786100822000&amp;api=v2"
 data-linked-resource-id="430408839" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50627.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50627</a>: Apache CXF: 
OAuth2: Missing JWT Audience and Issuer Validation in Access Token 
Validator</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50628.txt?version=2&amp;modificationDate=1786100892000&amp;api=v2"
 data-linked-resource-id="430408840" data-linked-resource-version="2" 
data-linked-resource-type="attac
 hment" data-linked-resource-default-alias="CVE-2026-50628.txt" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50628</a>: Apache CXF: 
OAuth2: Inverted IP Binding Check Defeats Security Control</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2026-50629.txt?version=2&amp;modificationDate=1786101020000&amp;api=v2"
 data-linked-resource-id="430408842" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50629.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50629</a>: Apache CXF: 
OAuth2: Log Injection via Unsanitized Client Identifier</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50630.txt?version=2&amp;modificationDate=1786101091000&amp;api=v2"
 d
 ata-linked-resource-id="430408843" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50630.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50630</a>: Apache CXF: 
OAuth2: HTTP Response Splitting via WWW-Authenticate Realm 
Injection&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50631.txt?version=2&amp;modificationDate=1786101161000&amp;api=v2"
 data-linked-resource-id="430408844" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50631.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50631</a>: Apache CXF: 
OAuth2: TOCTOU Race Condition in Refresh Token Processing</li><li><a sha
 pe="rect" 
href="security-advisories.data/CVE-2026-50632.txt?version=3&amp;modificationDate=1786101236000&amp;api=v2"
 data-linked-resource-id="430408845" data-linked-resource-version="3" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50632.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50632:</a> Apache CXF: 
JNDI Injection Vulnerability in JMSConfigFactory</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50633.txt?version=2&amp;modificationDate=1786101322000&amp;api=v2"
 data-linked-resource-id="430408847" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50633.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-506
 33</a>: Apache CXF: JNDI Injection vulnerability in 
DispatchMDBMessageListenerImpl</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50634.txt?version=2&amp;modificationDate=1786101412000&amp;api=v2"
 data-linked-resource-id="430408848" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50634.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50634</a>: Apache CXF: WS 
JSON request filter trusts metadata from an unvalidated first signature 
entry</li><li><a shape="rect" 
href="security-advisories.data/CVE-2026-50645.txt?version=4&amp;modificationDate=1786101529000&amp;api=v2"
 data-linked-resource-id="430408849" data-linked-resource-version="4" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-50645.txt" data-nice-type="Text 
File" data-linked-resource
 -content-type="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-50645</a>: Apache CXF: No 
restriction on attachment headers per message</li><li 
data-uuid="49670750-d78a-4fe2-a830-cc372623486a"><a shape="rect" 
href="security-advisories.data/CVE-2026-54225.txt?version=1&amp;modificationDate=1786010395000&amp;api=v2"
 data-linked-resource-id="446071159" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-54225.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-54225</a>: Apache CXF: 
Denial of Service attack via large attachments</li><li 
data-uuid="4d3b7d2a-2f95-4a2a-a0a4-16f3020d96a7"><a shape="rect" 
href="security-advisories.data/CVE-2026-57817.txt?version=1&amp;modificationDate=1786011692000&amp;api=v2"
 data-linked-resource-id="4460711
 72" data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-57817.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-57817</a>: Apache CXF: 
The authorization code hash (c_hash) is not enforced for the hybrid OIDC 
flow</li><li data-uuid="421dab32-bb7b-4d04-a713-bf4012dab629"><a shape="rect" 
href="security-advisories.data/CVE-2026-57818.txt?version=1&amp;modificationDate=1786011946000&amp;api=v2"
 data-linked-resource-id="446071174" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-57818.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-57818</a>: Apache CXF: 
OAuth2 Authorization Code Replay via TOCTOU in JCac
 heCodeDataProvider</li><li data-uuid="9d893f5b-4577-4891-9f8a-c2a20c2a5a4d"><a 
shape="rect" 
href="security-advisories.data/CVE-2026-57819.txt?version=1&amp;modificationDate=1786010722000&amp;api=v2"
 data-linked-resource-id="446071161" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-57819.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-57819</a>: Apache CXF: No 
default restriction on the amount of form parameters per message</li><li 
data-uuid="37f9ccab-4420-47c2-9438-12b46f6066e1"><a shape="rect" 
href="security-advisories.data/CVE-2026-61466.txt?version=1&amp;modificationDate=1786012193000&amp;api=v2"
 data-linked-resource-id="446071176" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-61466.txt" data-nice-type="Text 
File"
  data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-61466</a>: Apache CXF: 
OAuth2 Dynamic Client Registration Scope Self-Escalation</li><li 
data-uuid="7c0ccedd-3bf8-4f26-993b-1ee8e96c74a4"><a shape="rect" 
href="security-advisories.data/CVE-2026-63687.txt?version=2&amp;modificationDate=1786012916000&amp;api=v2"
 data-linked-resource-id="446071178" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-63687.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-63687</a>: Apache CXF: 
JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters</li><li 
data-uuid="497c4f06-b436-4629-aa2d-e022a5268c29"><a shape="rect" 
href="security-advisories.data/CVE-2026-64958.txt?version=1&amp;modificationDate=1786
 011007000&amp;api=v2" data-linked-resource-id="446071164" 
data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-64958.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-64958</a>: Apache CXF: 
Denial of service via message header attachments</li><li 
data-uuid="b0b1eaaa-380b-4004-acbf-c135ef8b97e1"><a shape="rect" 
href="security-advisories.data/CVE-2026-65432.txt?version=1&amp;modificationDate=1786011271000&amp;api=v2"
 data-linked-resource-id="446071166" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-65432.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-65432</a>: Apache CXF: 
XXE via WSDL/XSD import pa
 rsing</li><li data-uuid="7f19a0df-3457-45ef-bd8f-cfe71b66943c"><a shape="rect" 
href="security-advisories.data/CVE-2026-65583.txt?version=1&amp;modificationDate=1786013097000&amp;api=v2"
 data-linked-resource-id="446071184" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-65583.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-65583</a>: Apache CXF: 
Self-issued ID token claims validation skipped</li><li 
data-uuid="2693b482-0db3-4743-aa55-aec24d4be213"><a shape="rect" 
href="security-advisories.data/CVE-2026-66909.txt?version=2&amp;modificationDate=1786011477000&amp;api=v2"
 data-linked-resource-id="446071168" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-66909.txt" data-nice-type="Text 
File" data-linked-resource-content-type
 ="text/plain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-66909</a>: Apache CXF: 
Unsafe deserialization of inbound JMS ObjectMessage</li><li 
data-uuid="89ccf4e0-27b8-46a2-b30b-c382bf070593"><a shape="rect" 
href="security-advisories.data/CVE-2026-68079.txt?version=1&amp;modificationDate=1786013245000&amp;api=v2"
 data-linked-resource-id="446071186" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-68079.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-68079</a>: Apache CXF: 
DefaultEncryptingCodeDataProvider allows unlimited authorization code 
replay</li><li data-uuid="ab47b81c-be3b-460d-acdb-cb9a11f85d57"><a shape="rect" 
href="security-advisories.data/CVE-2026-68481.txt?version=3&amp;modificationDate=1786013432000&amp;api=v2"
 data-linked-
 resource-id="446071188" data-linked-resource-version="3" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-68481.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-68481</a>: Apache CXF: 
Revocation bypass in DefaultEncryptingOAuthDataProvider</li><li 
data-uuid="12d301a8-d0e6-4e39-8b16-fd1b95516d5b"><a shape="rect" 
href="security-advisories.data/CVE-2026-71575.txt?version=1&amp;modificationDate=1791535059000&amp;api=v2"
 data-linked-resource-id="451979418" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-71575.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-71575</a>: Apache CXF: 
Inoperative max_age authentication-freshness check in
  OidcClientCodeRequestFilter</li><li 
data-uuid="c650d80c-48b7-402b-8b92-bd571b7d8a0f"><a shape="rect" 
href="security-advisories.data/CVE-2026-73179.txt?version=1&amp;modificationDate=1791535144439&amp;api=v2"
 data-linked-resource-id="451979420" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-73179.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-73179</a>: Apache CXF: 
JPA authorization-code consume is non-atomic</li><li 
data-uuid="17b33361-b798-4722-a7f6-2fd7586cc513"><a shape="rect" 
href="security-advisories.data/CVE-2026-78384.txt?version=1&amp;modificationDate=1791535295000&amp;api=v2"
 data-linked-resource-id="451979422" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-78384.txt" data-nice-type="Text 
File" data-linked-
 resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-78384</a>: Apache CXF: 
Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing 
(Decompression Bomb)</li><li 
data-uuid="1e6fca12-2b04-420c-a385-fffa1a0fca97"><a shape="rect" 
href="security-advisories.data/CVE-2026-79650.txt?version=1&amp;modificationDate=1791535377000&amp;api=v2"
 data-linked-resource-id="451979424" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-79650.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-79650</a>: Apache CXF: 
OIDC RP Open Redirect</li><li 
data-uuid="ac364426-ccd8-4f1e-9f5a-89f359002858"><a shape="rect" 
href="security-advisories.data/CVE-2026-86463.txt?version=1&amp;modificationDate=1791535463880&amp;api=v2"
 data-link
 ed-resource-id="451979426" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-86463.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-86463</a>: Apache CXF: 
FIQL Query Parser Denial of Service</li><li 
data-uuid="bac9f372-a29f-4be7-9611-62415e6bbcf0"><a shape="rect" 
href="security-advisories.data/CVE-2026-97468.txt?version=1&amp;modificationDate=1791535537000&amp;api=v2"
 data-linked-resource-id="451979428" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-97468.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-97468</a>: Apache CXF: 
Authentication bypass via weak cache keys for validated STS tokens</li
 ><li data-uuid="b165ab94-8753-4b55-8744-18304275fb31"><a shape="rect" 
 >href="security-advisories.data/CVE-2026-97791.txt?version=1&amp;modificationDate=1791535604000&amp;api=v2"
 > data-linked-resource-id="451979431" data-linked-resource-version="1" 
 >data-linked-resource-type="attachment" 
 >data-linked-resource-default-alias="CVE-2026-97791.txt" data-nice-type="Text 
 >File" data-linked-resource-content-type="text/plain" 
 >data-linked-resource-container-id="27837502" 
 >data-linked-resource-container-version="107">CVE-2026-97791</a>: Apache CXF: 
 >STSTokenValidator can accept untrusted SAML assertions because it shares 
 >validation state between requests</li><li 
 >data-uuid="3113efe8-0622-455d-ae09-9ea2af4dd225"><a shape="rect" 
 >href="security-advisories.data/CVE-2026-100227.txt?version=1&amp;modificationDate=1791535675000&amp;api=v2"
 > data-linked-resource-id="451979433" data-linked-resource-version="1" 
 >data-linked-resource-type="attachment" 
 >data-linked-resource-default-alias="CVE-2026-100227.txt" data-ni
 ce-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-100227</a>: Apache CXF: 
XML Signature wrapping in JAX-RS XML Security</li><li 
data-uuid="d51941de-62fb-408d-a140-8ff81f7c05cc"><a shape="rect" 
href="security-advisories.data/CVE-2026-107937.txt?version=1&amp;modificationDate=1791537347073&amp;api=v2"
 data-linked-resource-id="451979441" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-107937.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-107937</a>: Apache CXF: 
The attachment header size and count limits can be bypassed, which allows 
denial of service through memory exhaustion.</li><li 
data-uuid="412ea718-e349-48c5-bf9a-ae7faca7c0c2"><a shape="rect" 
href="security-advisories.
 
data/CVE-2026-107938.txt?version=1&amp;modificationDate=1791537720451&amp;api=v2"
 data-linked-resource-id="451979444" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-107938.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2026-107938</a>: Apache CXF: 
The Netty HTTP client transport does not perform TLS hostname 
verification.</li><li data-uuid="18580a98-f189-4d9b-a70e-ea440acf1c9b"><a 
shape="rect" 
href="security-advisories.data/CVE-2026-108039.txt?version=1&amp;modificationDate=1791538183000&amp;api=v2"
 data-linked-resource-id="451979451" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2026-108039.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-linked-
 resource-container-version="107">CVE-2026-108039</a>: Apache CXF: Prevent 
unbounded XML document size in StaxUtils by adding default element and 
character limits</li></ul><h3 id="SecurityAdvisories-2025">2025</h3><ul><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-23184.txt?version=2&amp;modificationDate=1737381863000&amp;api=v2"
 data-linked-resource-id="340036025" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-23184.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2025-23184</a>: Apache CXF: 
Denial of Service vulnerability with temporary files&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48795.txt?version=1&amp;modificationDate=1752578416000&amp;api=v2"
 data-linked-resource-id="373886120" data-linked-resource-version="1" 
data-linked-resource-type="attachm
 ent" data-linked-resource-default-alias="CVE-2025-48795.txt" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2025-48795</a>: Apache CXF: 
Denial of Service and sensitive data exposure in logs&#160;</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2025-48913.txt?version=1&amp;modificationDate=1754576095000&amp;api=v2"
 data-linked-resource-id="373887565" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2025-48913.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2025-48913</a>: Apache CXF: 
Untrusted JMS configuration can lead to RCE&#160;</li></ul><h3 
id="SecurityAdvisories-2024">2024</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2024-28752.txt?version=2&amp;
 modificationDate=1710431346000&amp;api=v2" data-linked-resource-id="296290905" 
data-linked-resource-version="2" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-28752.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2024-28752</a>: Apache CXF 
SSRF Vulnerability using the Aegis databinding&#160;</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-29736.txt?version=1&amp;modificationDate=1721314668000&amp;api=v2"
 data-linked-resource-id="315493016" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-29736.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2024-29736</a>: SSRF 
vulnerability via WADL stylesheet parameter</li><li><a sha
 pe="rect" 
href="security-advisories.data/CVE-2024-32007.txt?version=1&amp;modificationDate=1721314761000&amp;api=v2"
 data-linked-resource-id="315493017" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-32007.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2024-32007</a>: Apache CXF 
Denial of Service vulnerability in JOSE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2024-41172.txt?version=1&amp;modificationDate=1721314821000&amp;api=v2"
 data-linked-resource-id="315493018" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2024-41172.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2024-41172</a>: Un
 restricted memory consumption in CXF HTTP clients</li></ul><h3 
id="SecurityAdvisories-2022">2022</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46363.txt?version=1&amp;modificationDate=1670942001000&amp;api=v2"
 data-linked-resource-id="235836918" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46363.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2022-46363</a>: Apache CXF 
directory listing / code exfiltration</li><li><a shape="rect" 
href="security-advisories.data/CVE-2022-46364.txt?version=1&amp;modificationDate=1670944473000&amp;api=v2"
 data-linked-resource-id="235836926" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2022-46364.txt" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain"
  data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2022-46364</a>: Apache CXF 
SSRF Vulnerability</li></ul><h3 
id="SecurityAdvisories-2021">2021</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2021-30468.txt.asc?version=1&amp;modificationDate=1623835370000&amp;api=v2"
 data-linked-resource-id="181310680" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2021-30468.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2021-30468</a>: Apache CXF 
Denial of service vulnerability in parsing JSON via 
JsonMapObjectReaderWriter</li><li><a shape="rect" 
href="security-advisories.data/CVE-2021-22696.txt.asc?version=1&amp;modificationDate=1617355743000&amp;api=v2"
 data-linked-resource-id="177049091" data-linked-resource-version="1" 
data-linked-resource-type
 ="attachment" data-linked-resource-default-alias="CVE-2021-22696.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2021-22696</a>: OAuth 2 
authorization service vulnerable to DDos attacks</li></ul><h3 
id="SecurityAdvisories-2020">2020</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2020-13954.txt.asc?version=1&amp;modificationDate=1605183671000&amp;api=v2"
 data-linked-resource-id="165225095" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-13954.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2020-13954</a>: Apache CXF 
Reflected XSS in the services listing page via the styleSheetPath</li><li><a 
shape="rect" href="security-advisories.data/CVE-2020-195
 4.txt.asc?version=1&amp;modificationDate=1585730169000&amp;api=v2" 
data-linked-resource-id="148645097" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2020-1954.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2020-1954</a>: Apache CXF JMX 
Integration is vulnerable to a MITM attack</li></ul><h3 
id="SecurityAdvisories-2019">2019</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2019-17573.txt.asc?version=2&amp;modificationDate=1584610519000&amp;api=v2"
 data-linked-resource-id="145722246" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-17573.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-
 2019-17573</a>: Apache CXF Reflected XSS in the services listing 
page</li><li><a shape="rect" 
href="security-advisories.data/CVE-2019-12423.txt.asc?version=1&amp;modificationDate=1579178393000&amp;api=v2"
 data-linked-resource-id="145722244" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12423.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2019-12423</a>: Apache CXF 
OpenId Connect JWK Keys service returns private/secret credentials if 
configured with a jwk keystore</li><li><a shape="rect" 
href="security-advisories.data/CVE-2019-12419.txt.asc?version=2&amp;modificationDate=1572961201000&amp;api=v2"
 data-linked-resource-id="135859612" data-linked-resource-version="2" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12419.txt.asc" 
data-nice-type="Text File
 " data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2019-12419</a>: Apache CXF 
OpenId Connect token service does not properly validate the clientId</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2019-12406.txt.asc?version=1&amp;modificationDate=1572957147000&amp;api=v2"
 data-linked-resource-id="135859607" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2019-12406.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2019-12406</a>: Apache CXF 
does not restrict the number of message attachments</li></ul><h3 
id="SecurityAdvisories-2018">2018</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2018-8039.txt.asc?version=1&amp;modificationDate=1530184663000&amp;api=v2"
 data-linked-resource-id
 ="87296645" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8039.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2018-8039</a>: Apache CXF TLS 
hostname verification does not work correctly with com.sun.net.ssl.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2018-8038.txt.asc?version=1&amp;modificationDate=1530712328000&amp;api=v2"
 data-linked-resource-id="87297524" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2018-8038.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2018-8038</a>: Apache CXF 
Fediz is vulnerable to DTD based XML attacks</li></ul><h3 
id="SecurityAdvisories-2017">2017</h
 3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12631.txt.asc?version=1&amp;modificationDate=1512037276000&amp;api=v2"
 data-linked-resource-id="74688816" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12631.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2017-12631</a>: CSRF 
vulnerabilities in the Apache CXF Fediz Spring plugins.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-12624.txt.asc?version=1&amp;modificationDate=1510661632000&amp;api=v2"
 data-linked-resource-id="74687100" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-12624.txt.asc" 
data-nice-type="Text File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-linked-resource-contai
 ner-version="107">CVE-2017-12624</a>: Apache CXF web services that process 
attachments are vulnerable to Denial of Service (DoS) attacks.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2017-7662.txt.asc?version=1&amp;modificationDate=1494949377000&amp;api=v2"
 data-linked-resource-id="70255583" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7662.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2017-7662</a>: The Apache CXF 
Fediz OIDC Client Registration Service is vulnerable to CSRF 
attacks.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-7661.txt.asc?version=1&amp;modificationDate=1494949364000&amp;api=v2"
 data-linked-resource-id="70255582" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-7661.
 txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2017-7661</a>: The Apache CXF 
Fediz Jetty and Spring plugins are vulnerable to CSRF attacks.</li><li><a 
shape="rect" 
href="security-advisories.data/CVE-2017-5656.txt.asc?version=1&amp;modificationDate=1492515113000&amp;api=v2"
 data-linked-resource-id="69406543" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5656.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2017-5656</a>: Apache CXF's 
STSClient uses a flawed way of caching tokens that are associated with 
delegation tokens.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-5653.txt.asc?version=1&amp;modificationDate=1492515074000&amp;api=v2"
 data-li
 nked-resource-id="69406542" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-5653.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2017-5653</a>: Apache CXF 
JAX-RS XML Security streaming clients do not validate that the service response 
was signed or encrypted.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2017-3156.txt.asc?version=1&amp;modificationDate=1487590374000&amp;api=v2"
 data-linked-resource-id="68715428" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2017-3156.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2017-3156</a>: Apache CXF 
OAuth2 Hawk and JOSE MAC Validation code is v
 ulnerable to the timing attacks</li></ul><h3 
id="SecurityAdvisories-2016">2016</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2016-8739.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635454" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-8739.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2016-8739</a>: Atom entity 
provider of Apache CXF JAX-RS is vulnerable to XXE</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-6812.txt.asc?version=1&amp;modificationDate=1482164360000&amp;api=v2"
 data-linked-resource-id="67635455" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-6812.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/p
 lain" data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2016-6812</a>: XSS risk in 
Apache CXF FormattedServiceListWriter when a request URL contains matrix 
parameters</li><li><a shape="rect" 
href="security-advisories.data/CVE-2016-4464.txt.asc?version=1&amp;modificationDate=1473350153000&amp;api=v2"
 data-linked-resource-id="65869472" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2016-4464.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2016-4464</a>: Apache CXF 
Fediz application plugins do not match the SAML AudienceRestriction values 
against the list of configured audience URIs</li></ul><h3 
id="SecurityAdvisories-2015">2015</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5253.txt.asc?version=1&amp;modificationDate=1447433340000
 &amp;api=v2" data-linked-resource-id="61328642" 
data-linked-resource-version="1" data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5253.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2015-5253</a>: Apache CXF SAML 
SSO processing is vulnerable to a wrapping attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2015-5175.txt.asc?version=1&amp;modificationDate=1440598018000&amp;api=v2"
 data-linked-resource-id="61316328" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2015-5175.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2015-5175</a>: Apache CXF 
Fediz application plugins are vulnerable to Denial of Service (DoS) attacks
 </li></ul><h3 id="SecurityAdvisories-2014">2014</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3577.txt.asc?version=1&amp;modificationDate=1419245371000&amp;api=v2"
 data-linked-resource-id="51183657" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3577.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-3577</a>: Apache CXF SSL 
hostname verification bypass</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3566.txt.asc?version=1&amp;modificationDate=1418740474000&amp;api=v2"
 data-linked-resource-id="50561078" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3566.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502"
  data-linked-resource-container-version="107">Note on CVE-2014-3566</a>: SSL 
3.0 support in Apache CXF, aka the "POODLE" attack.</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3623.txt.asc?version=1&amp;modificationDate=1414169368000&amp;api=v2"
 data-linked-resource-id="47743195" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-3623.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-3623</a>: Apache CXF does 
not properly enforce the security semantics of SAML SubjectConfirmation methods 
when used with the TransportBinding</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-3584.txt.asc?version=1&amp;modificationDate=1414169326000&amp;api=v2"
 data-linked-resource-id="47743194" data-linked-resource-version="1" 
data-linked-resource-type="attachment" data-linked-
 resource-default-alias="CVE-2014-3584.txt.asc" data-nice-type="Text File" 
data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-3584</a>: Apache CXF 
JAX-RS SAML handling is vulnerable to a Denial of Service (DoS) 
attack</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0109.txt.asc?version=1&amp;modificationDate=1398873370000&amp;api=v2"
 data-linked-resource-id="40895138" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0109.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-0109</a>: HTML content 
posted to SOAP endpoint could cause OOM errors</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0110.txt.asc?version=1&amp;modificationDate=1398873378000&amp;api=v2"
 data-lin
 ked-resource-id="40895139" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0110.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-0110</a>: Large invalid 
content could cause temporary space to fill</li><li><a shape="rect" 
href="security-advisories.data/CVE-2014-0034.txt.asc?version=1&amp;modificationDate=1398873385000&amp;api=v2"
 data-linked-resource-id="40895140" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0034.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-0034</a>: The 
SecurityTokenService accepts certain invalid SAML Tokens as valid</li><li><a 
shape="rect" href="security-adviso
 
ries.data/CVE-2014-0035.txt.asc?version=1&amp;modificationDate=1398873391000&amp;api=v2"
 data-linked-resource-id="40895141" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2014-0035.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" 
data-linked-resource-container-version="107">CVE-2014-0035</a>: UsernameTokens 
are sent in plaintext with a Symmetric EncryptBeforeSigning policy</li></ul><h3 
id="SecurityAdvisories-2013">2013</h3><ul><li><a shape="rect" 
href="security-advisories.data/CVE-2013-2160.txt.asc?version=1&amp;modificationDate=1372324301000&amp;api=v2"
 data-linked-resource-id="33095710" data-linked-resource-version="1" 
data-linked-resource-type="attachment" 
data-linked-resource-default-alias="CVE-2013-2160.txt.asc" data-nice-type="Text 
File" data-linked-resource-content-type="text/plain" 
data-linked-resource-container-id="27837502" data-li
 nked-resource-container-version="107">CVE-2013-2160</a> - Denial of Service 
Attacks on Apache CXF</li><li><a shape="rect" href="cve-2012-5575.html">Note on 
CVE-2012-5575</a> - XML Encryption backwards compatibility attack on Apache 
CXF.</li><li><a shape="rect" href="cve-2013-0239.html">CVE-2013-0239</a> - 
Authentication bypass in the case of WS-SecurityPolicy enabled plaintext 
UsernameTokens.</li></ul><h3 id="SecurityAdvisories-2012">2012</h3><ul><li><a 
shape="rect" href="cve-2012-5633.html">CVE-2012-5633</a> - WSS4JInInterceptor 
always allows HTTP Get requests from browser.</li><li><a shape="rect" 
href="note-on-cve-2011-2487.html">Note on CVE-2011-2487</a> - Bleichenbacher 
attack against distributed symmetric key in WS-Security.</li><li><a 
shape="rect" href="cve-2012-3451.html">CVE-2012-3451</a> - Apache CXF is 
vulnerable to SOAP Action spoofing attacks on Document Literal web 
services.</li><li><a shape="rect" href="cve-2012-2379.html">CVE-2012-2379</a> - 
Apache CXF does not verify
  that elements were signed or encrypted by a particular Supporting 
Token.</li><li><a shape="rect" href="cve-2012-2378.html">CVE-2012-2378</a> - 
Apache CXF does not pick up some child policies of WS-SecurityPolicy 1.1 
SupportingToken policy assertions on the client side.</li><li><a shape="rect" 
href="note-on-cve-2011-1096.html">Note on CVE-2011-1096</a> - XML Encryption 
flaw / Character pattern encoding attack.</li><li><a shape="rect" 
href="cve-2012-0803.html">CVE-2012-0803</a> - Apache CXF does not validate 
UsernameToken policies correctly.</li></ul><h3 
id="SecurityAdvisories-2010">2010</h3><ul><li><a shape="rect" 
class="external-link" 
href="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf";>CVE-2010-2076</a>
 - DTD based XML attacks.</li></ul><p><br clear="none"></p></div>
            </div>
            <!-- Content -->
          </td>

Reply via email to