Apache CXF < 4.1.7 / 4.2.x < 4.2.2 Multiple Vulnerabilities

high Nessus Plugin ID 321189

Synopsis

Apache CXF is affected by multiple vulnerabilities.

Description

The version of Apache CXF installed on the remote host is prior to 4.1.7 or 4.2.x prior to 4.2.2. It is, therefore, affected by multiple vulnerabilities, including:

- A JNDI Injection vulnerability in the JCA integration module allows code execution if an attacker can manipulate the JCA deployment descriptor or runtime activation parameters.
(CVE-2026-50633)

- An incomplete fix for CVE-2026-44417 allows code execution if untrusted users are allowed to configure JMS for Apache CXF. (CVE-2026-50632)

- No restriction on the amount of attachment headers in a message during deserialization can lead to uncontrolled resource consumption or denial of service. (CVE-2026-50645)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache CXF version 4.1.7, or 4.2.2 or later.

See Also

https://cxf.apache.org/security-advisories.html

https://lists.apache.org/thread/1czhgovkgzdkyp3t61wthn0foogh2grf

https://lists.apache.org/thread/740ghch5z5y675cn2kzgtyo5k37n6qcw

https://lists.apache.org/thread/24zb7cqcvykhwm0j797dmdq25s61mj93

https://lists.apache.org/thread/s83t3x4r626o9h8rt0ryr1w7w53l1vv8

https://lists.apache.org/thread/9nfwh9d3m4kznxrk1mz98hl0jml18k0p

https://lists.apache.org/thread/bt7vnjzzkpd6vdhkxv103poor1jy5trm

https://lists.apache.org/thread/ydzj8m5mqmjy13xgyj9mkk9hfff63qq7

https://lists.apache.org/thread/xw95po30p8th58ms1no6b0f2375cql00

Plugin Details

Severity: High

ID: 321189

File Name: apache_cxf_4_2_2.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 6/16/2026

Updated: 6/16/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-50633

CVSS v3

Risk Factor: High

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:apache:cxf

Required KB Items: installed_sw/Apache CXF

Patch Publication Date: 6/11/2026

Vulnerability Publication Date: 6/11/2026

Reference Information

CVE: CVE-2026-50623, CVE-2026-50629, CVE-2026-50630, CVE-2026-50631, CVE-2026-50632, CVE-2026-50633, CVE-2026-50634, CVE-2026-50645