Resource Exhaustion Vulnerability in StaxUtils by Apache
CVE-2026-108039
What is CVE-2026-108039?
The StaxUtils library by Apache contains a vulnerability that allows for resource exhaustion through unbounded XML document processing. By default, there is no limit on the number of elements or characters in an XML document, which means that large requests can lead to excessive memory and CPU usage during parsing. This issue is particularly concerning when Apache CXF constructs a DOM from the input, potentially resulting in denial-of-service conditions if application limits are not properly configured. To mitigate this vulnerability, users are encouraged to upgrade to versions 4.2.4, 4.1.9, or 3.6.13, where sensible defaults for maximum element count and document size have been implemented.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13