目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Apache CXF 产品漏洞列表 / CVE 中文分析 48

Apache CXF 产品相关 48 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。

Apache CXF 是一款流行的 Java Web 服务框架,本页面聚合了与该软件相关的各类安全漏洞,涵盖远程代码执行、跨站脚本及反序列化风险等类型。收录范围从早期版本发布至今,完整记录了受影响版本及修复状态。读者可通过本页追踪 Apache 官方安全公告,深入了解框架在序列化、XML 解析等方面的常见弱点机制,并检索特定版本的历史漏洞详情,以便评估升级需求或排查潜在风险,为系统安全加固提供数据支持。

ベンダー: Apache Software Foundation

CVE IDタイトルCVSS深刻度公開日
CVE-2026-57818 Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider CWE-367--2026-08-06
CVE-2026-61466 Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation CWE-304--2026-08-06
CVE-2026-63687 Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters CWE-345--2026-08-06
CVE-2026-65583 Apache CXF: Self-issued ID token claims validation skipped CWE-345--2026-08-06
CVE-2026-68079 Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay CWE-294--2026-08-06
CVE-2026-68481 Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider CWE-672--2026-08-06
CVE-2026-65432 Apache CXF: XXE via WSDL/XSD import parsing CWE-611--2026-08-06
CVE-2026-57817 Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow CWE-20--2026-08-06
CVE-2026-66909 Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage CWE-502--2026-08-06
CVE-2026-64958 Apache CXF: Denial of service via message header attachments CWE-400--2026-08-06
CVE-2026-57819 Apache CXF: No default restriction on the amount of form parameters per message CWE-400--2026-08-06
CVE-2026-54225 Apache CXF: Denial of Service attack via large attachments CWE-770--2026-08-06
CVE-2026-50645 Apache CXF: No restriction on attachment headers per message CWE-400--2026-06-12
CVE-2026-50634 Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry CWE-347--2026-06-12
CVE-2026-50633 Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl CWE-20--2026-06-12
CVE-2026-50632 Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory CWE-20--2026-06-12
CVE-2026-50631 Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing CWE-367--2026-06-12
CVE-2026-50630 Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection CWE-113--2026-06-12
CVE-2026-50629 Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier CWE-93--2026-06-12
CVE-2026-50628 Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control CWE-20--2026-06-12
CVE-2026-50627 Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator CWE-289--2026-06-12
CVE-2026-49875 Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils CWE-611--2026-06-12
CVE-2026-50623 Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService CWE-287--2026-06-12
CVE-2026-44417 Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE) CWE-20--2026-05-22
CVE-2026-44618 Apache CXF: XXE vulnerability in WS-Transfer functionality CWE-611--2026-05-22
CVE-2026-44930 Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository CWE-90--2026-05-22
CVE-2025-48913 Apache CXF: Untrusted JMS configuration can lead to RCE CWE-20 9.8 -2025-08-08
CVE-2025-48795 Apache CXF: Denial of Service and sensitive data exposure in logs CWE-400 5.5 -2025-07-15
CVE-2025-23184 Apache CXF: Denial of Service vulnerability with temporary files CWE-400 5.9 Medium2025-01-21
CVE-2024-41172 Apache CXF: Unrestricted memory consumption in CXF HTTP clients CWE-401 7.5 -2024-07-19

Apache CXF 产品累计公开 48 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。