VendorsApachecxfall versions
Vulnerabilities

Apache Cxf

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2012-2379
Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
Published 2013-01-03 · Modified
10.0EPSS 0.041
CVE-2019-12419
Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.
Published 2019-11-06 · Modified
9.8EPSS 0.138
CVE-2010-2076
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
Published 2010-08-19 · Modified
9.8EPSS 0.098
CVE-2012-0803
The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request.
Published 2017-08-08 · Modified
9.8EPSS 0.035
CVE-2022-46364
Apache CXF SSRF Vulnerability
Published 2022-12-13 · Modified
9.8EPSS 0.022
CVE-2025-48913
Apache CXF: Untrusted JMS configuration can lead to RCE
Published 2025-08-08 · Modified
9.8EPSS 0.008
CVE-2026-44930
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
Published 2026-05-22 · Modified
9.8EPSS 0.007
CVE-2026-50628
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
Published 2026-06-12 · Modified
9.8EPSS 0.007
CVE-2026-66909
Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
Published 2026-08-06 · Modified
9.8EPSS 0.007
CVE-2026-49875
Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils
Published 2026-06-12 · Modified
9.8EPSS 0.005
CVE-2026-68079
Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
Published 2026-08-06 · Modified
9.8EPSS 0.004
CVE-2024-28752
Apache CXF SSRF Vulnerability using the Aegis databinding
Published 2024-03-15 · Analyzed
9.3EPSS 0.025
CVE-2024-29736
Apache CXF: SSRF vulnerability via WADL stylesheet parameter
Published 2024-07-19 · Modified
9.1EPSS 0.010
CVE-2026-50627
Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
Published 2026-06-12 · Modified
9.1EPSS 0.004
CVE-2026-61466
Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
Published 2026-08-06 · Modified
9.1EPSS 0.004
CVE-2026-63687
Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
Published 2026-08-06 · Modified
9.1EPSS 0.003
CVE-2026-65583
Apache CXF: Self-issued ID token claims validation skipped
Published 2026-08-06 · Modified
9.1EPSS 0.003
CVE-2026-50632
Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory
Published 2026-06-12 · Modified
8.8EPSS 0.006
CVE-2018-8039
It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.
Published 2018-07-02 · Modified
8.1EPSS 0.085
CVE-2026-50633
Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
Published 2026-06-12 · Modified
8.1EPSS 0.009
CVE-2026-57817
Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow
Published 2026-08-06 · Modified
8.1EPSS 0.004
CVE-2026-57818
Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider
Published 2026-08-06 · Modified
8.1EPSS 0.003
CVE-2016-8739
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.
Published 2017-08-10 · Modified
7.8EPSS 0.073
CVE-2021-40690
Bypass of the secureValidation property
Published 2021-09-19 · Modified
7.5EPSS 0.074
CVE-2021-30468
Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter
Published 2021-06-16 · Modified
7.5EPSS 0.070
CVE-2017-5656
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
Published 2017-04-18 · Modified
7.5EPSS 0.068
CVE-2021-22696
OAuth 2 authorization service vulnerable to DDos attacks
Published 2021-04-02 · Modified
7.5EPSS 0.066
CVE-2017-3156
The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
Published 2017-08-10 · Modified
7.5EPSS 0.063
CVE-2019-12423
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry. This case is not vulnerable. However it is also possible to obtain the keys from a JWK keystore file, by setting the configuration parameter "rs.security.keystore.type" to "jwk". For this case all keys are returned in this file "as is", including all private key and secret key credentials. This is an obvious security risk if the user has configured the signature keystore file with private or secret key credentials. From CXF 3.3.5 and 3.2.12, it is mandatory to specify an alias corresponding to the id of the key in the JWK file, and only this key is returned. In addition, any private key information is omitted by default. "oct" keys, which contain secret keys, are not returned at all.
Published 2020-01-16 · Modified
7.5EPSS 0.061
CVE-2025-23184
Apache CXF: Denial of Service vulnerability with temporary files
Published 2025-01-21 · Modified
7.5EPSS 0.021
CVE-2024-32007
Apache CXF Denial of Service vulnerability in JOSE
Published 2024-07-19 · Modified
7.5EPSS 0.013
CVE-2022-46363
Apache CXF directory listing / code exfiltration
Published 2022-12-13 · Modified
7.5EPSS 0.012
CVE-2024-41172
Apache CXF: Unrestricted memory consumption in CXF HTTP clients
Published 2024-07-19 · Modified
7.5EPSS 0.012
CVE-2026-44417
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
Published 2026-05-22 · Modified
7.5EPSS 0.006
CVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Published 2026-08-06 · Modified
7.5EPSS 0.005
CVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Published 2026-08-06 · Modified
7.5EPSS 0.005
CVE-2026-50645
Apache CXF: No restriction on attachment headers per message
Published 2026-06-12 · Modified
7.5EPSS 0.005
CVE-2026-68481
Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
Published 2026-08-06 · Modified
7.5EPSS 0.004
CVE-2026-65432
Apache CXF: XXE via WSDL/XSD import parsing
Published 2026-08-06 · Modified
7.5EPSS 0.004
CVE-2026-64958
Apache CXF: Denial of service via message header attachments
Published 2026-08-06 · Analyzed
7.5EPSS 0.004
1 / 2Next →