Impact
An incomplete fix for a prior CVE means that Apache CXF can still be subjected to denial of service attacks when a client sends a message with an unusually large number of attachment headers. The vulnerability results in excessive resource consumption, potentially crashing or slowing the CXF service, and the weakness corresponds to CWE‑400, a resource‑exhaustion flaw.
Affected Systems
All versions of Apache Software Foundation Apache CXF released before the fixes are deployed are affected. The remedial versions are 4.2.3, 4.1.8, and 3.6.12; installing any of those resolves the issue.
Risk and Exploitability
Exploit requires crafting a request that includes many attachment headers, a technique that can be performed over the network to any CXF endpoint. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog, so there is no known active exploitation in the wild; however, the lack of a remedial release increases the potential for future attacks. The remote‑network attack vector and lack of throttling suggest that an adversary only needs network access to a vulnerable service to trigger the denial of service.
OpenCVE Enrichment