CVE-2026-44618

Apache CXF: XXE vulnerability in WS-Transfer functionality

Title source: cna
STIX 2.1

Description

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

References (1)

Core 1
Core References

Scores

EPSS 0.0003
EPSS Percentile 8.4%

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (3)
Apache Software Foundation/Apache CXF < 3.6.11
Apache Software Foundation/Apache CXF 4.0.0 - 4.1.6
Apache Software Foundation/Apache CXF 4.2.0 - 4.2.1
Published May 22, 2026
Tracked Since May 22, 2026