Security Advisory

CVE-2026-44618

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-22 12:17:14
Last updated 2026-05-22 21:26:21
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.