Impact
By default, StaxUtils places no limit on the number of elements or total characters in an XML document. When Apache CXF builds a DOM from the input—such as during SAAJ or WS‑Security processing—a very large request can consume excessive memory and CPU. This uncontrolled resource consumption can cripple a service and cause a denial of service. The weakness is an uncontrolled resource consumption flaw.
Affected Systems
The vulnerability affects Apache CXF releases prior to 4.2.4, 4.1.9, and 3.6.13. All deployments of Apache CXF that use the default StaxUtils configuration are exposed, because the limits are only 100× the default maximum child elements (5,000,000) and a 256MB character cap if overridden. The affected component is the XML parsing layer used by CXF applications.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV. An adversary can exploit the flaw by sending an oversized XML payload to a CXF‑enabled service over a network. No authentication or execution is required; the attack is performed with standard HTTP requests. The resulting high CPU and memory consumption may crash the service or deny legitimate traffic. Because the flaw is a DoS and not an arbitrary code execution, the risk level is high but the exploitation vector is straightforward.
OpenCVE Enrichment