https://seclists.org/oss-sec/2026/q3/470: CVE-2026-64958: Apache CXF: Denial of service via message header attachments
Published Aug 6, 2026
·Updated
Affected Software
3 affected components
Apache CXF<4.2.3
Apache CXF>=4.0.0<4.1.8
Apache CXF<3.6.12
Frequently Asked Questions
1
What is the severity of CVE-2026-64958?
CVE-2026-64958 has a moderate severity level.
2
Which versions of Apache CXF are affected by CVE-2026-64958?
Apache CXF versions 4.2.0 before 4.2.3, 4.0.0 before 4.1.8, and all versions before 3.6.12 are affected.
3
How do I fix CVE-2026-64958?
To fix CVE-2026-64958, upgrade Apache CXF to version 4.2.3, 4.1.8, or 3.6.12 or later.
4
What type of vulnerability is CVE-2026-64958?
CVE-2026-64958 is a Denial of Service vulnerability resulting from message header attachments.
5
Is there a prior vulnerability related to CVE-2026-64958?
Yes, CVE-2026-64958 is an incomplete fix for the previously reported CVE-2026-50645.