THREAT OPS › Threat News › CVE-2026-64958: Apache CXF: Denial of service via message header attachments
CVE-2026-64958: Apache CXF: Denial of service via message header attachments
<p>Posted by Colm O hEigeartaigh on Aug 06</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache CXF (org.apache.cxf:cxf-core) 4.2.0 before 4.2.3<br /> - Apache CXF (org.apache.cxf:cxf-core) 4.0.0 before 4.1.8<br /> - Apache CXF (org.apache.cxf:cxf-core) before 3.6.12<br /> <br /> Description:<br /> <br /> An incomplete fix for CVE-2026-50645 means that it is still possible
Indicators of compromise
- CVE-2026-64958cve
- CVE-2026-50645cve
Original source: https://seclists.org/oss-sec/2026/q3/470