What is CVE-2026-64958?
An incomplete fix for CVE-2026-50645 still allows a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are advised to upgrade to versions 4.2.3, 4.1.8, or 3.6.12 to resolve the issue.
Azərbaycanca: CVE-2026-50645 üçün əvvəlki düzəliş natamam olduğu üçün Apache CXF-də hələ də denial of service (DoS) hücumu mümkündür. Təcavüzkar çox sayda attachment başlığı olan mesaj göndərərək servisi sıradan çıxara bilər. İstifadəçilərə 4.2.3, 4.1.8 və ya 3.6.12 versiyalarına yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which versions of Apache CXF are affected by CVE-2026-64958?
The vulnerability affects Apache CXF versions prior to 4.2.3, 4.1.8, and 3.6.12. Users are advised to upgrade to these versions to resolve the issue.
How can an attacker exploit CVE-2026-64958?
An attacker can exploit CVE-2026-64958 by sending a message with many attachment headers, causing a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.