{"id":"CVE-2026-50645","aliases":["GHSA-ghvc-7hp8-2g2v"],"url":"https://o3.security/vulnerability/CVE-2026-50645","summary":"Apache CXF: No restriction on attachment headers per message","details":"There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue by imposing a maximum default of 500 attachments per message.","published":"2026-06-12T09:06:54.819Z","modified":"2026-08-09T03:30:12.288647917Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00476,"percentile":0.38722,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.cxf:cxf-core","fixedVersion":"4.2.2"},{"ecosystem":"Maven","name":"org.apache.cxf:cxf-core","fixedVersion":"4.1.7"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/11/12"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50645.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/24zb7cqcvykhwm0j797dmdq25s61mj93"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50645"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-09T03:30:12.288647917Z"}}