CVE-2026-86463
Received Received - Intake

FIQL Parser Denial of Service in Apache CXF

Vulnerability report for CVE-2026-86463, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Apache Software Foundation

Description

Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions. The search pattern can get stuck trying many combinations when it encounters a long string without an operator, causing the parser to consume excessive CPU time. An attacker can send a crafted query to make the server use up CPU resources, potentially slowing down or stopping other requests. The fix was to limit FIQL expressions to 4 KiB by default, preventing attackers from sending extremely long inputs while still allowing normal queries. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Apache Software Foundation Apache CXF 4.2.0
Apache Software Foundation Apache CXF 4.0.0
Apache Software Foundation Apache CXF 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache CXF's FIQL query parser has a flaw where it inefficiently searches for operators in query expressions. When a long string without an operator is encountered, the parser tries many combinations, consuming excessive CPU time. Attackers can exploit this by sending crafted queries to overload server resources.

Detection Guidance

Monitor CPU usage spikes during query processing. Check Apache CXF server logs for unusually long or malformed FIQL queries. Use network traffic analysis tools to detect abnormally large query strings.

Impact Analysis

This vulnerability can cause server slowdowns or crashes by consuming excessive CPU resources. It may disrupt normal operations, degrade performance for other users, and potentially lead to denial-of-service conditions if exploited.

Mitigation Strategies

Upgrade Apache CXF to version 4.2.4, 4.1.9, or 3.6.13. Implement input validation to limit query length to 4 KiB. Configure rate limiting for query requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86463. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart