CVE-2026-107937
Received Received - Intake

Denial of Service in Apache CXF via Unbounded Multipart Headers

Vulnerability report for CVE-2026-107937, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Apache Software Foundation

Description

In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service.Β  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Apache Software Foundation Apache CXF 4.2.0
Apache Software Foundation Apache CXF 4.0.0
Apache Software Foundation Apache CXF 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache CXF involves improper enforcement of attachment header size and count limits. The parser did not correctly apply the attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. Attackers could exploit this by sending multipart requests with excessively large or repeated headers, causing unbounded memory allocation and a denial of service.

Detection Guidance

This vulnerability can be detected by monitoring Apache CXF servers for unusually large or repeated multipart headers. Check server logs for requests exceeding default header size or count limits. Use network monitoring tools to inspect incoming multipart requests for header anomalies.

Impact Analysis

If you use Apache CXF, an attacker could exploit this to crash your server by sending specially crafted requests. This could disrupt services, cause downtime, and potentially lead to data unavailability. Upgrading to fixed versions (4.2.4, 4.1.9, or 3.6.13) is recommended to mitigate the risk.

Mitigation Strategies

Immediately upgrade Apache CXF to versions 4.2.4, 4.1.9, or 3.6.13. If upgrading is not possible, apply strict input validation to block oversized or malformed multipart headers. Monitor server memory usage and network traffic for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107937. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart