Apache CXF 的 JMS 传输组件会对任何传入的 JMS ObjectMessage 的消息体使用原生 Java 反序列化机制进行处理,且未实施任何类型限制。任何能够向服务的 JMS 目的地发送消息的攻击者,均可提交一个恶意的序列化对象,从而导致拒绝服务(DoS);如果类路径中存在合适的利用链类(gadget class),还可能引发远程代码执行(RCE)。该漏洞的修复方案默认禁用了 ObjectMessage 的反序列化功能,并提供配置开关以便在必要时重新启用。建议用户升级至已修复此问题的版本,包括 4.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0< 4.2.3 |
affected |
4.0.0< 4.1.8 |
affected | ||
< 3.6.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 ~ 4.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64640 | 5.3 MEDIUM | Apache Polaris: register endpoint reads attacker-controlled storage location before allowe |
| CVE-2026-65583 | Apache CXF: Self-issued ID token claims validation skipped | |
| CVE-2025-49506 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash | |
| CVE-2026-34191 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle | |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | |
| CVE-2026-57818 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider | |
| CVE-2026-61466 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation | |
| CVE-2026-63687 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters | |
| CVE-2026-68079 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay | |
| CVE-2026-68481 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider | |
| CVE-2026-65432 | Apache CXF: XXE via WSDL/XSD import parsing | |
| CVE-2026-57817 | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow | |
| CVE-2026-64958 | Apache CXF: Denial of service via message header attachments | |
| CVE-2026-57819 | Apache CXF: No default restriction on the amount of form parameters per message | |
| CVE-2026-54225 | Apache CXF: Denial of Service attack via large attachments |
No comments yet