Denial of Service Vulnerability in Apache CXF for Multipart/MTOM Attachments
CVE-2026-107937
What is CVE-2026-107937?
In Apache CXF, a vulnerability exists in the multipart/MTOM attachment header parser that fails to enforce limits on attachment-header size and count properly. Specifically, the limits on header values do not account for continuation lines or the overall number of header lines. This oversight allows a remote, unauthenticated attacker to exploit the system by sending multipart requests with excessively large headers, leading to unbounded memory allocation on the server. Consequently, this can result in a denial of service, impacting the availability and performance of the affected systems. Users are advised to upgrade to the specified versions to rectify this vulnerability.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13