Nikhil created TOMEE-4680:
-----------------------------
Summary: Apache CXF - CVE-2026-54225
Key: TOMEE-4680
URL: https://issues.apache.org/jira/browse/TOMEE-4680
Project: TomEE
Issue Type: Dependency upgrade
Components: TomEE Core Server
Affects Versions: 10.2.0
Reporter: Nikhil
Apache CXF allows to control the maximum attachment size via theÂ
"attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there
was no default placed on this size, meaning that a denial of service attack is
possible if the user doesn't explicitly set the limit. Users should update to
Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a
default attachment size limit of 50mb.
Apache TomEE 10.2.0 ships CXF 4.1.7 and fix is currently available through *CXF
4.1.8*
--
This message was sent by Atlassian Jira
(v8.20.10#820010)