What is CVE-2026-54225?
CVE-2026-54225 was found in Apache CXF, where the lack of a default limit on the "attachment-max-size" attribute allows a denial of service attack if no explicit limit is set. This affects systems using Apache CXF versions prior to 4.2.3, 4.1.8, and 3.6.12. Updating to the patched versions is recommended to mitigate the issue.
Azərbaycanca: CVE-2026-54225 Apache CXF-də aşkar edilib, burada "attachment-max-size" atributu üçün standart məhdudiyyət olmadığından, istifadəçi limit təyin etməsə, xidmət inkarı hücumu mümkündür. Bu, xüsusilə Apache CXF 4.2.3, 4.1.8 və 3.6.12 versiyalarından əvvəlki versiyalardan istifadə edən sistemlərə təsir edir. Problemi aradan qaldırmaq üçün həll edilmiş versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
What is the impact of CVE-2026-54225 on Apache CXF?
CVE-2026-54225 allows a Denial of Service attack due to the lack of a default limit on the "attachment-max-size" attribute.
To which Apache CXF versions should I upgrade to mitigate CVE-2026-54225?
To mitigate the vulnerability, upgrade to Apache CXF versions 4.2.3, 4.1.8, 3.6.12 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.