CVE-2026-64958

CVE-2026-64958: Apache CXF: Denial of service via message header attachments

Vendor Apache Software Foundation
Product Apache CXF
Weakness CWE-400
Published August 6, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated