Vulnerability in CompressionUtils of Apache Products Enables Uncontrolled Decompression
CVE-2026-78384

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-78384?

The CompressionUtils component of Apache products contains a vulnerability that allows attacker-controlled DEFLATE data to be decompressed without an output-size limitation. This can lead to resource exhaustion as a small, specially crafted payload can expand to gigabytes in memory. The vulnerability can be exploited through mechanisms like JWE decryption and SAML redirect/POST binding token inflation, where decompression occurs before any trust validation checks. To mitigate this issue, a maximum size cap for inflated data has been implemented, defaulting to 10 MiB, and users are urged to update to the latest secure versions.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guanping Zhang reported this vulnerability.
.