AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-54225

HIGH · CVSS 7.5 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache CXF versions prior to 4.2.3, 4.1.8, and 3.6.12 are vulnerable due to the absence of a default maximum attachment size, which could lead to denial of service attacks if users do not manually configure this limit. Organizations using affected versions should prioritize updating to the specified releases to mitigate the risk of service disruption. This vulnerability particularly impacts developers and system administrators managing web services with Apache CXF.

CVE
CVE-2026-54225
Severity
HIGH
CVSS
7.5
EPSS
0.47%
Apache

Original NVD Description

Apache CXF allows to control the maximum attachment size via theĀ "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.

Related CVEs

Other vulnerabilities affecting the same vendor(s)