Description

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.

Severity (CVSS)

Base score7.5
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Provided byCISA-ADP

Weaknesses

  • CWE-770 — CWE-770 Allocation of Resources Without Limits or Throttling

Affected products

VendorProductVersions
Apache Software FoundationApache CXF4.2.0 to <4.2.3; 4.0.0 to <4.1.8; 0 to <3.6.12

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 07 Aug 2026 07:02 UTC.