Vulnerability in CompressionUtils of Apache Products Enables Uncontrolled Decompression
CVE-2026-78384
Currently unrated
What is CVE-2026-78384?
The CompressionUtils component of Apache products contains a vulnerability that allows attacker-controlled DEFLATE data to be decompressed without an output-size limitation. This can lead to resource exhaustion as a small, specially crafted payload can expand to gigabytes in memory. The vulnerability can be exploited through mechanisms like JWE decryption and SAML redirect/POST binding token inflation, where decompression occurs before any trust validation checks. To mitigate this issue, a maximum size cap for inflated data has been implemented, defaulting to 10 MiB, and users are urged to update to the latest secure versions.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13