Overview
About vulnerability
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.Details
- Affected product:
- Apache CXF , Wildfly , camel , chemistry-opencmis , tika , wildfly
- Affected packages:
- cxf-services-sts-core @ 3.5.11 (+1945 more)