Bug 2548457 (CVE-2026-108039) - CVE-2026-108039 org.apache.cxf/cxf-core: Apache CXF: Denial of Service via unrestricted XML parsing
Summary: CVE-2026-108039 org.apache.cxf/cxf-core: Apache CXF: Denial of Service via un...
Keywords:
Status: NEW
Alias: CVE-2026-108039
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-09 10:31 UTC by OSIDB Bzimport
Modified: 2026-10-09 13:56 UTC (History)
45 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-09 10:31:35 UTC
By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or WS-Security), and could cause a denial of service when no request size limit was configured. Both limits now have defaults: the maximum element count is 100 × maxChildElements (5,000,000 by default), and the maximum document size is 256M characters. Applications that process larger documents can raise the limits with the org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters properties.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.


Note You need to log in before you can comment on or make changes to this bug.