Security Advisory

CVE-2026-64958

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-06 10:13:04
Last updated 2026-08-06 15:10:53
Assigner apache
CVSS score not scored
State PUBLISHED

Description

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.