HIGH7.5
GHSA-fh5r-crhr-qrrq
Apache CXF: Denial of Service vulnerability with temporary files
Quick fix
GHSA-fh5r-crhr-qrrq — org.apache.cxf:cxf-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.5.10</version> for org.apache.cxf:cxf-coreDetails
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.cxf:cxf-core
Introduced in:
0Fixed in: 3.5.10Fix
# pom.xml: bump <version>3.5.10</version> for org.apache.cxf:cxf-coreMaven/org.apache.cxf:cxf-core
Introduced in:
3.6.0Fixed in: 3.6.5Fix
# pom.xml: bump <version>3.6.5</version> for org.apache.cxf:cxf-coreMaven/org.apache.cxf:cxf-core
Introduced in:
4.0.0Fixed in: 4.0.6Fix
# pom.xml: bump <version>4.0.6</version> for org.apache.cxf:cxf-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-23184[ADVISORY]
- https://github.com/apache/cxf/pull/2048[WEB]
- https://github.com/apache/cxf/pull/2111[WEB]
- https://github.com/apache/cxf[PACKAGE]
- https://issues.apache.org/jira/browse/CXF-7396[WEB]
- https://lists.apache.org/thread/lfs8l63rnctnj2skfrxyys7v8fgnt122[WEB]
- https://security.netapp.com/advisory/ntap-20250214-0003[WEB]
- https://www.vicarius.io/vsociety/posts/cve-2025-23184-detect-apache-cxf-vulnerability[WEB]
- https://www.vicarius.io/vsociety/posts/cve-2025-23184-mitigate-apache-cxf-vulnerability[WEB]
- http://www.openwall.com/lists/oss-security/2025/01/20/3[WEB]