Apache CXF 通过其加固的 StaxUtils 路径解析顶层 WSDL 文件,该路径已禁用 XML DTD 和外部实体。然而,从该顶层 WSDL 引用的任何 或 元素会被交由 WSDL4J 处理,而 WSDL4J 并未禁用 DOCTYPE 声明或外部实体。因此,应用于顶层文档的安全防护措施并未延伸至被导入的文档,导致导入的 WSDL/XSD 内容易受 XML 外部实体(XXE)攻击。建议用户升级至修复了此问题的版本 4.2.3、4.1.8 或 3.6.12。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0< 4.2.3 |
affected |
4.0.0< 4.1.8 |
affected | ||
< 3.6.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 ~ 4.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64640 | 5.3 MEDIUM | Apache Polaris: register endpoint reads attacker-controlled storage location before allowe |
| CVE-2026-65583 | Apache CXF: Self-issued ID token claims validation skipped | |
| CVE-2026-54225 | Apache CXF: Denial of Service attack via large attachments | |
| CVE-2026-57819 | Apache CXF: No default restriction on the amount of form parameters per message | |
| CVE-2026-64958 | Apache CXF: Denial of service via message header attachments | |
| CVE-2026-66909 | Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage | |
| CVE-2026-57817 | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow | |
| CVE-2026-68481 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider | |
| CVE-2026-68079 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay | |
| CVE-2025-49506 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | |
| CVE-2026-63687 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters | |
| CVE-2026-61466 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation | |
| CVE-2026-57818 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider | |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | |
| CVE-2026-34191 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle | |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash |
No comments yet