CVE-2024-41172
HIGHApache Cxf < 3.6.4 - Memory Leak
Title source: ruleDescription
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Scores
CVSS v3
7.5
EPSS
0.0089
EPSS Percentile
75.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-401
Status
published
Affected Products (2)
apache/cxf
< 3.6.4
org.apache.cxf/cxf-rt-transports-http
< 4.0.5Maven
Timeline
Published
Jul 19, 2024
Tracked Since
Feb 18, 2026