[
https://issues.apache.org/jira/browse/TOMEE-4680?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Nikhil updated TOMEE-4680:
--------------------------
Summary: Apache CXF - CVE-2026-54225 in TomEE 10.2.0 (was: Apache CXF -
CVE-2026-54225)
> Apache CXF - CVE-2026-54225 in TomEE 10.2.0
> -------------------------------------------
>
> Key: TOMEE-4680
> URL: https://issues.apache.org/jira/browse/TOMEE-4680
> Project: TomEE
> Issue Type: Dependency upgrade
> Components: TomEE Core Server
> Affects Versions: 10.2.0
> Reporter: Nikhil
> Priority: Critical
>
> Apache CXF allows to control the maximum attachment size via theÂ
> "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there
> was no default placed on this size, meaning that a denial of service attack
> is possible if the user doesn't explicitly set the limit. Users should update
> to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a
> default attachment size limit of 50mb.
>
> Apache TomEE 10.2.0 ships CXF 4.1.7 and fix is currently available through
> *CXF 4.1.8*
--
This message was sent by Atlassian Jira
(v8.20.10#820010)