
CVE-2026-54225 Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on… https://www.cve.org/CVERecord?id=CVE-2026-54225
Post summary
Announces CVE-2026-54225 in Apache CXF, describing how the maximum attachment size is configurable without defaults in older releases, with a link to the official CVE record.

