https://seclists.org/oss-sec/2026/q3/468: CVE-2026-54225: Apache CXF: Denial of Service attack via large attachments
Published Aug 6, 2026
·Updated
Affected Software
3 affected components
Apache CXF>=4.2.0<4.2.3
Apache CXF>=4.0.0<4.1.8
Apache CXF<3.6.12
Frequently Asked Questions
1
What is the severity of CVE-2026-54225?
The severity of CVE-2026-54225 is classified as low.
2
Which versions of Apache CXF are affected by CVE-2026-54225?
CVE-2026-54225 affects Apache CXF versions 4.2.0 before 4.2.3, 4.0.0 before 4.1.8, and any version before 3.6.12.
3
How do I fix CVE-2026-54225?
To fix CVE-2026-54225, upgrade Apache CXF to version 4.2.3 or later, 4.1.8 or later, or 3.6.12 or later.
4
What is the impact of CVE-2026-54225 on systems?
CVE-2026-54225 allows for a Denial of Service attack through the exploitation of large attachments.
5
Is it necessary to update if using a later version of Apache CXF?
If you are using a version of Apache CXF later than the affected versions, you are not impacted by CVE-2026-54225.