漏洞描述: CompressionUtils.inflate() 方法在解压攻击者控制的 DEFLATE 格式数据时,未设置输出大小的上限。攻击者可构造一个体积较小(约 KB 级别)的恶意载荷,在解压后导致堆内存膨胀至 GB 级别,从而引发拒绝服务或内存耗尽攻击。该漏洞可通过以下两种途径触发: 1. JWE 解密过程中,当压缩方式为 时(例如使用 RSA-OAEP 密钥包装的 JoseSessionTokenProvider); 2. SAML 重定向或 POST 绑定方式下的令牌解压过程。 在上述两种场景中,解压
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 ~ 4.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103413 | 8.8 HIGH | Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes |
| CVE-2026-103412 | 8.8 HIGH | Apache Camel Karavan: project file name path traversal when committing a project to Git |
| CVE-2026-108039 | Apache CXF: Prevent unbounded XML document size in StaxUtils by adding default element and | |
| CVE-2026-107938 | Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification. | |
| CVE-2026-107937 | Apache CXF: The attachment header size and count limits can be bypassed, which allows deni | |
| CVE-2026-100227 | Apache CXF: XML Signature wrapping in JAX-RS XML Security | |
| CVE-2026-97791 | Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares valid | |
| CVE-2026-97468 | Apache CXF: Authentication bypass via weak cache keys for validated STS tokens | |
| CVE-2026-86463 | Apache CXF: FIQL Query Parser Denial of Service | |
| CVE-2026-79650 | Apache CXF: OIDC RP Open Redirect | |
| CVE-2026-73179 | Apache CXF: JPA authorization-code consume is non-atomic | |
| CVE-2026-71575 | Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFil |
No comments yet