Description
In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service. 
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Upgrade
AI Analysis

Impact

A flaw in the multipart/MTOM attachment header parser bypasses the limits on header size and count, allowing a remote, unauthenticated attacker to send malformed multipart requests that cause the server to allocate unlimited memory. If exploited, the application can become unresponsive or crash, preventing normal operation and denying service to legitimate users. The weakness is a classic resource exhaustion failure due to missing input validation.

Affected Systems

The issue affects the Apache CXF framework produced by the Apache Software Foundation. Any deployment of CXF v4.2.x, v4.1.x, or v3.6.x that has not been upgraded to the security releases (4.2.4, 4.1.9, or 3.6.13 respectively) is susceptible. Versions prior to those releases and any builds using these libraries are at risk unless mitigations are applied.

Risk and Exploitability

Although the EPSS score is not available, the vulnerability is severe because it relies on a simple multipart request and does not require authentication. The exploit is straightforward once the attacker can send large folded or repeated headers to the server. The lack of a KEV listing does not diminish the potential impact; the DoS can be triggered from external networks, making it a high-priority threat that demands immediate attention.

Generated by OpenCVE AI on October 9, 2026 at 11:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patches corresponding to CXF 4.2.4, 4.1.9, or 3.6.13 to enforce header size and count limits.
  • If an immediate patch is not possible, restrict the size of incoming multipart requests or reject requests with large folded headers at the gateway or load balancer.
  • Reconfigure or disable MTOM support if the functionality is not required, or set stricter memory quotas for the application to limit the impact of any potential exploitation.

Generated by OpenCVE AI on October 9, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-400

Fri, 09 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service.  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Title Apache CXF: The attachment header size and count limits can be bypassed, which allows denial of service through memory exhaustion.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-09T11:07:52.472Z

Reserved: 2026-10-09T09:12:15.139Z

Link: CVE-2026-107937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T11:17:02.107

Modified: 2026-10-09T11:17:02.107

Link: CVE-2026-107937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption