CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-50645

HIGH
7.5
CVSS Severity Score
EPSS Score0.0900%
EPSS Percentile11.95th
Published2026年6月12日
Last Modified2026年6月13日

Vulnerability Description

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue by imposing a maximum default of 500 attachments per message.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報