Impact
Apache CXF allows administrators to control the maximum size of attachments through the "attachment-max-size" setting. Prior to versions 4.2.3, 4.1.8, and 3.6.12, no default size limit was enforced. This omission permits an attacker to send exceedingly large attachments, overwhelming system resources and causing the service to become unavailable. The vulnerability falls under CWE‑770, indicating that it arises from unchecked resource consumption.
Affected Systems
The affected product is Apache CXF, maintained by the Apache Software Foundation. Versions before 4.2.3, 4.1.8, and 3.6.12 are impacted. Users should verify that they are not running any of these legacy releases.
Risk and Exploitability
While an official EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the lack of a size constraint introduces a high likelihood of successful denial‑of‑service exploitation, especially when an attacker can submit large payloads to the service. The attack vector is inferred to be remote, given that the vulnerability is triggered by external attachment submissions. The damage profile is high, as resource exhaustion can render the impacted service—and potentially dependent systems—unresponsive until remedial action is taken.
OpenCVE Enrichment