Resource Exhaustion Vulnerability in Apache CXF's FIQL Query Parser
CVE-2026-86463

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-86463?

The FIQL query parser in Apache CXF is susceptible to a resource exhaustion vulnerability due to its inefficient handling of operators in query expressions. When confronted with long input strings void of operators, the parser can enter a loop, resulting in excessive CPU resource consumption. This situation can degrade the server's performance, causing slow responses or even halting processing of additional requests. To mitigate this risk, a safeguard has been implemented that restricts the length of FIQL expressions to a maximum of 4 KiB, thereby enabling normal query execution while thwarting malicious attempts to exploit the vulnerability. Users are advised to upgrade to version 4.2.4 or higher, or version 4.1.9 or 3.6.13 to ensure protection against this issue.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Read (github.com/Michael-JRead)
.