CVE-2026-108039
Received Received - Intake

XML External Entity Processing Vulnerability in Apache CXF

Vulnerability report for CVE-2026-108039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Apache Software Foundation

Description

By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or WS-Security), and could cause a denial of service when no request size limit was configured. Both limits now have defaults: the maximum element count is 100 Γ— maxChildElements (5,000,000 by default), and the maximum document size is 256M characters. Applications that process larger documents can raise the limits with the org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters properties. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Apache Software Foundation Apache CXF 4.2.0
Apache Software Foundation Apache CXF 4.0.0
Apache Software Foundation Apache CXF 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Apache CXF's StaxUtils allowing unlimited XML document size and element count during parsing. Without size limits, large requests could consume excessive memory and CPU, leading to denial of service. The issue is fixed in versions 4.2.4, 4.1.9, or 3.6.13 by setting default limits of 5,000,000 elements and 256M characters.

Detection Guidance

This vulnerability can be detected by monitoring for unusually high memory or CPU usage during XML parsing, especially in applications using Apache CXF. Check for large XML requests or responses that may exceed default limits. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this by sending a very large XML request, causing high memory and CPU usage. This may lead to system slowdowns, crashes, or unavailability of services relying on Apache CXF for XML processing.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It primarily impacts system performance and availability by allowing denial-of-service attacks through excessive memory and CPU usage during XML parsing. Compliance risks would arise only if the vulnerability leads to unauthorized data access or service disruptions affecting regulated data processing.

Mitigation Strategies

Upgrade Apache CXF to versions 4.2.4, 4.1.9, or 3.6.13 or later. Configure request size limits using the org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters properties if processing large documents.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108039. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart