
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50645 is a denial-of-service vulnerability in Apache CXF caused by the absence of any restriction on the number of attachment headers a message can contain during deserialization. An unauthenticated remote attacker can exploit this to cause uncontrolled resource consumption and make the service unavailable. The vulnerability affects Apache CXF (org.apache.cxf:cxf-core) versions before 4.1.7 and versions 4.2.0 through 4.2.2 (exclusive). It was disclosed on June 11, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Apache Advisory, oss-security).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). During message deserialization, Apache CXF imposes no upper bound on the number of attachment headers a message may include, allowing an attacker to craft messages with an arbitrarily large number of attachment headers that force the server to allocate excessive resources. No authentication or special privileges are required, and the attack vector is entirely network-based with low complexity. The fix enforces a default maximum of 500 attachments per message (oss-security, Apache Advisory).
Successful exploitation results in a denial-of-service condition, exhausting server resources and rendering the Apache CXF-based service unavailable to legitimate users. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Services relying on Apache CXF for SOAP or REST message processing are at risk of complete service disruption (oss-security, Apache Advisory).
Content-Disposition or similar MIME headers) within a single request.Content-Type: multipart/... headers.Users should upgrade Apache CXF to version 4.1.7 (for the 4.1.x branch) or 4.2.2 (for the 4.2.x branch), which enforce a default maximum of 500 attachment headers per message. No configuration-based workaround has been officially documented; upgrading is the recommended and primary remediation. Organizations unable to upgrade immediately should consider placing a WAF or reverse proxy in front of CXF endpoints to limit the size and complexity of inbound MIME multipart messages (Apache Advisory, oss-security).
The vulnerability was reported by the Apache CXF team with a severity rating of "low" in the oss-security disclosure, reflecting the limited scope of impact (availability only) and the absence of known exploits. A Tenable Nessus detection plugin (ID 321189) was published to assist organizations in identifying vulnerable instances. Social media activity was minimal, with brief mentions on Bluesky and Mastodon security feeds (oss-security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."