
CVE-2026-57819 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit … https://www.cve.org/CVERecord?id=CVE-2026-57819
Post summary
The CVE entry notes that Apache CXF can limit form parameters via the maxFormParameterCount option, but no default limit is applied.


