CVE-2026-44618: Apache CXF: XXE vulnerability in WS-Transfer functionality
Colm O hEigeartaigh <[email protected]> Fri, 22 May 2026 12:11:59 +0100
| Newsgroups | gmane.comp.version-control.subversion.user,gmane.comp.apache.cxf.devel |
|---|---|
| Message-ID | <CAB8XdGDDrbzqt0k59UkJ565KnzpQ5XCihNa1H+g4rkKoBV8jAw__12418.5886279278$1779448351$gmane$org@mail.gmail.com> |
Severity: important Affected versions: - Apache CXF (org.apache.cxf:cxf-rt-ws-transfer) 4.2.0 before 4.2.1 - Apache CXF (org.apache.cxf:cxf-rt-ws-transfer) 4.0.0 before 4.1.6 - Apache CXF (org.apache.cxf:cxf-rt-ws-transfer) before 3.6.11 Description: Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue. Credit: Credit to IcySun ([email protected]), =E5=B9=BF=E4=B8=9C=E4=B8=9C=E6=96=B9=E6= =80=9D=E7=BB=B4=E7=A7=91=E6=8A=80=E6=9C=89=E9=99=90=E5=85=AC=E5=8F=B8 (find= er) References: https://cxf.apache.org/ https://www.cve.org/CVERecord?id=3DCVE-2026-44618