CVE-2026-44618: Apache CXF: XXE vulnerability in WS-Transfer functionality

Colm O hEigeartaigh <[email protected]> Fri, 22 May 2026 12:11:59 +0100
Newsgroups gmane.comp.version-control.subversion.user,gmane.comp.apache.cxf.devel
Message-ID <CAB8XdGDDrbzqt0k59UkJ565KnzpQ5XCihNa1H+g4rkKoBV8jAw__12418.5886279278$1779448351$gmane$org@mail.gmail.com>
Severity: important

Affected versions:

- Apache CXF (org.apache.cxf:cxf-rt-ws-transfer) 4.2.0 before 4.2.1
- Apache CXF (org.apache.cxf:cxf-rt-ws-transfer) 4.0.0 before 4.1.6
- Apache CXF (org.apache.cxf:cxf-rt-ws-transfer) before 3.6.11

Description:

Insecure XML parser configuration in Apache CXF's WS-Transfer module
may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11,
which fix this issue.

Credit:

Credit to IcySun ([email protected]), =E5=B9=BF=E4=B8=9C=E4=B8=9C=E6=96=B9=E6=
=80=9D=E7=BB=B4=E7=A7=91=E6=8A=80=E6=9C=89=E9=99=90=E5=85=AC=E5=8F=B8 (find=
er)

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=3DCVE-2026-44618