Impact
A flaw in the multipart/MTOM attachment header parser bypasses the limits on header size and count, allowing a remote, unauthenticated attacker to send malformed multipart requests that cause the server to allocate unlimited memory. If exploited, the application can become unresponsive or crash, preventing normal operation and denying service to legitimate users. The weakness is a classic resource exhaustion failure due to missing input validation.
Affected Systems
The issue affects the Apache CXF framework produced by the Apache Software Foundation. Any deployment of CXF v4.2.x, v4.1.x, or v3.6.x that has not been upgraded to the security releases (4.2.4, 4.1.9, or 3.6.13 respectively) is susceptible. Versions prior to those releases and any builds using these libraries are at risk unless mitigations are applied.
Risk and Exploitability
Although the EPSS score is not available, the vulnerability is severe because it relies on a simple multipart request and does not require authentication. The exploit is straightforward once the attacker can send large folded or repeated headers to the server. The lack of a KEV listing does not diminish the potential impact; the DoS can be triggered from external networks, making it a high-priority threat that demands immediate attention.
OpenCVE Enrichment