CVE Tools

Apache Cxf

47 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apache Cxf, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Apache Cxf CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache Cxf CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-081
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-053
2026-0611
2026-070
2026-0812
2026-090

Severity

How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1430%
  • High2145%
  • Medium1226%

Latest CVEs

The 15 most recently published vulnerabilities affecting Apache Cxf.

  1. CVE-2026-57818Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider8.1
  2. CVE-2026-61466Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation9.1
  3. CVE-2026-63687Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters9.1
  4. CVE-2026-65583Apache CXF: Self-issued ID token claims validation skipped9.1
  5. CVE-2026-68079Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay9.8
  6. CVE-2026-68481Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider7.5
  7. CVE-2026-65432Apache CXF: XXE via WSDL/XSD import parsing7.5
  8. CVE-2026-57817Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow8.1
  9. CVE-2026-66909Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage9.8
  10. CVE-2026-64958Apache CXF: Denial of service via message header attachments7.5
  11. CVE-2026-57819Apache CXF: No default restriction on the amount of form parameters per message7.5
  12. CVE-2026-54225Apache CXF: Denial of Service attack via large attachments7.5
  13. CVE-2026-50645Apache CXF: No restriction on attachment headers per message7.5
  14. CVE-2026-50634Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry6.5
  15. CVE-2026-50633Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store