apache / cxf
27 known vulnerabilities in apache cxf.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40690 | Medium | 7.4% | 7.5 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.… | |
| CVE-2026-50633 | Medium | 0.9% | 8.1 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integrati… | |
| CVE-2026-44930 | Medium | 0.7% | 9.8 | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s… | |
| CVE-2026-50628 | Medium | 0.7% | 9.8 | A logic error in OAuthRequestFilter rejects legitimate requests originating from… | |
| CVE-2026-66909 | Medium | 0.7% | 9.8 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessag… | |
| CVE-2026-50632 | Medium | 0.6% | 8.1 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS c… | |
| CVE-2026-44417 | Medium | 0.6% | 7.5 | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to … | |
| CVE-2026-49875 | Medium | 0.5% | 9.8 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct … | |
| CVE-2026-54225 | Medium | 0.5% | 7.5 | Apache CXF allows to control the maximum attachment size via the "attachment-max… | |
| CVE-2026-57819 | Medium | 0.5% | 7.5 | Apache CXF allows to set a limit on the number of form parameters in a JAX-RS me… | |
| CVE-2026-50645 | Medium | 0.5% | 7.5 | There is no restriction on the amount of attachment headers that a message can c… | |
| CVE-2026-57817 | Medium | 0.4% | 8.1 | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the… | |
| CVE-2026-50627 | Medium | 0.4% | 9.1 | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Aud… | |
| CVE-2026-68481 | Medium | 0.4% | 7.5 | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still … | |
| CVE-2026-61466 | Medium | 0.4% | 9.1 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization s… | |
| CVE-2026-65432 | Medium | 0.4% | 7.5 | Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which dis… | |
| CVE-2026-64958 | Medium | 0.4% | 7.5 | An incomplete fix for CVE-2026-50645 means that it is still possible to perform … | |
| CVE-2026-68079 | Medium | 0.4% | 9.8 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code… | |
| CVE-2026-57818 | Medium | 0.3% | 8.1 | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single… | |
| CVE-2026-50631 | Medium | 0.3% | 7.4 | A race condition in AbstractOAuthDataProvider allows concurrent requests using t… | |
| CVE-2026-63687 | Medium | 0.3% | 9.1 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT in… | |
| CVE-2026-65583 | Medium | 0.3% | 9.1 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tok… | |
| CVE-2026-50629 | Low | 0.4% | 5.3 | The 'clientId' parameter from incoming HTTP requests is directly concatenated in… | |
| CVE-2026-50630 | Low | 0.4% | 6.5 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. Wh… | |
| CVE-2026-50623 | Low | 0.4% | 4.8 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionSe… | |
| CVE-2026-44618 | Low | 0.3% | 5.3 | Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow a… | |
| CVE-2026-50634 | Low | 0.3% | 6.5 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited t… |