CVE-2026-44618
Apache CXF: XXE vulnerability in WS-Transfer functionality
Title source: cnaDescription
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/c7vb015f8ljmjl44030mn0yfq71f7sd7
Scores
EPSS
0.0003
EPSS Percentile
8.4%
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-611
Status
published
Products (3)
Apache Software Foundation/Apache CXF
< 3.6.11
Apache Software Foundation/Apache CXF
4.0.0 - 4.1.6
Apache Software Foundation/Apache CXF
4.2.0 - 4.2.1
Published
May 22, 2026
Tracked Since
May 22, 2026