Nikhil created TOMEE-4680:
-----------------------------

             Summary: Apache CXF - CVE-2026-54225
                 Key: TOMEE-4680
                 URL: https://issues.apache.org/jira/browse/TOMEE-4680
             Project: TomEE
          Issue Type: Dependency upgrade
          Components: TomEE Core Server
    Affects Versions: 10.2.0
            Reporter: Nikhil


Apache CXF allows to control the maximum attachment size via the 
"attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there 
was no default placed on this size, meaning that a denial of service attack is 
possible if the user doesn't explicitly set the limit. Users should update to 
Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a 
default attachment size limit of 50mb.

 

Apache TomEE 10.2.0 ships CXF 4.1.7 and fix is currently available through *CXF 
4.1.8*



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to