📦 Cxf

by Apache

🔍 What is Cxf?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-48913

CRITICAL CVSS 9.8 Aug 8, 2025

This vulnerability in Apache CXF allows untrusted users who can configure JMS endpoints to use RMI or LDAP URLs, potentially leading to remote code execution. Systems where untrusted users have JMS co...

CVE-2024-29736

CRITICAL CVSS 9.1 Jul 19, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache CXF's WADL service description. It allows attackers to make unauthorized requests from the vulnerable server to internal...

CVE-2024-28752

CRITICAL CVSS 9.3 Mar 15, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache CXF's Aegis DataBinding component. It allows attackers to make unauthorized HTTP requests from the vulnerable server to ...

CVE-2024-41172

HIGH CVSS 7.5 Jul 19, 2024

This memory leak vulnerability in Apache CXF HTTP client conduit prevents proper garbage collection of HTTPClient instances, causing continuous memory consumption increase. Affected systems running Ap...

CVE-2021-30468

HIGH CVSS 7.5 Jun 16, 2021

A denial-of-service vulnerability in Apache CXF's JsonMapObjectReaderWriter allows attackers to send specially crafted JSON payloads to web services, causing infinite loops that consume 100% CPU on af...