Denial of Service Vulnerability in Apache CXF for Multipart/MTOM Attachments
CVE-2026-107937

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107937?

In Apache CXF, a vulnerability exists in the multipart/MTOM attachment header parser that fails to enforce limits on attachment-header size and count properly. Specifically, the limits on header values do not account for continuation lines or the overall number of header lines. This oversight allows a remote, unauthenticated attacker to exploit the system by sending multipart requests with excessively large headers, leading to unbounded memory allocation on the server. Consequently, this can result in a denial of service, impacting the availability and performance of the affected systems. Users are advised to upgrade to the specified versions to rectify this vulnerability.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects and independently by Mike Read (github.com/Michael-JRead)
.