CVE-2026-57819

Published: Ago 06, 2026 Last Modified: Ago 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the 'maxFormParameterCount' configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
Technologies: Not Technology-Specific, AI/ML
View CWE Details
Application

Cxf by Apache

Version Range Affected
To 3.6.12 (exclusive)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Cxf by Apache

Version Range Affected
From 4.0.0 (inclusive)
To 4.1.8 (exclusive)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Cxf by Apache

Version Range Affected
From 4.2.0 (inclusive)
To 4.2.3 (exclusive)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://www.openwall.com/lists/oss-security/2026/08/06/15
https://lists.apache.org/thread/2n14mk01bjc3lrsyhzrkwy8h86289mov