https://seclists.org/oss-sec/2026/q3/469: CVE-2026-57819: Apache CXF: No default striction on the amount of form parameters per message
Published Aug 6, 2026
·Updated
Affected Software
3 affected components
Apache Apache CXF>4.2.0<4.2.3
Apache Apache CXF>4.0.0<4.1.8
Apache Apache CXF<3.6.12
Frequently Asked Questions
1
What is the severity of CVE-2026-57819?
The severity of CVE-2026-57819 is classified as low.
2
Which versions of Apache CXF are affected by CVE-2026-57819?
Affected versions include Apache CXF 4.2.0 before 4.2.3, 4.0.0 before 4.1.8, and any version before 3.6.12.
3
How do I fix CVE-2026-57819?
To fix CVE-2026-57819, you should upgrade your Apache CXF to version 4.2.3 or higher, 4.1.8 or higher, or 3.6.12 or higher.
4
What is the impact of CVE-2026-57819?
CVE-2026-57819 allows setting limits on the number of form parameters per message, potentially leading to denial of service.
5
Is there a workaround for CVE-2026-57819?
There is no official workaround for CVE-2026-57819; upgrading to a patched version is recommended.