[ 
https://issues.apache.org/jira/browse/TOMEE-4680?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Richard Zowalla closed TOMEE-4680.
----------------------------------
    Fix Version/s: 11.0.0
                   10.3.0
       Resolution: Fixed

> Apache CXF - CVE-2026-54225 in TomEE 10.2.0
> -------------------------------------------
>
>                 Key: TOMEE-4680
>                 URL: https://issues.apache.org/jira/browse/TOMEE-4680
>             Project: TomEE
>          Issue Type: Dependency upgrade
>          Components: TomEE Core Server
>    Affects Versions: 10.2.0
>            Reporter: Nikhil
>            Priority: Critical
>             Fix For: 11.0.0, 10.3.0
>
>
> Apache CXF allows to control the maximum attachment size via the 
> "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there 
> was no default placed on this size, meaning that a denial of service attack 
> is possible if the user doesn't explicitly set the limit. Users should update 
> to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a 
> default attachment size limit of 50mb.
>  
> Apache TomEE 10.2.0 ships CXF 4.1.7 and fix is currently available through 
> *CXF 4.1.8*



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to