Apache CXF Denial-of-Service Vulnerability in Temporary File Handling

Vulnerability

A denial-of-service vulnerability has been identified in Apache CXF versions prior to 3.5.10, 3.6.0 prior to 3.6.5, and 4.0.0 prior to 4.0.6. In certain edge cases, instances of CachedOutputStream may not be properly closed. If these instances are backed by temporary files, they can accumulate and potentially fill up the file system, affecting both server and client environments.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, causing system resources to be exhausted and potentially disrupting normal operations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.