CVE-2026-64958Disclosure(apache / cxf)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apache cxf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cxf

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
cxf

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-06: 3Patch / Workaround · 2026-08-06: 1Technical Details · 2026-08-06: 208-06
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-64958 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment hea… https://www.cve.org/CVERecord?id=CVE-2026-64958

    Post summary

    The text highlights that an incomplete fix for CVE‑2026‑50645 leaves Apache CXF vulnerable to denial‑of‑service attacks via messages with many attachment headers.

    010001.5K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-64958 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment hea… https://www.cve.org/CVERecord?id=CVE-2026-64958 ----- Traducción: CVE-2026-64958 Una… http://infoflow.cloud`

    Post summary

    The text discloses that CVE-2026-64958 remains exploitable as a denial‑of‑service attack on Apache CXF due to an incomplete fix, without providing a PoC, exploit, or patch information.

    0000038
    97 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-64958 Denial of Service in Apache CXF via Multiple Attachment Headers CVE-2026-50645 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-64958

    Post summary

    The post merely lists CVE identifiers and a link to a vulnerability database without providing further technical information or actionable details.

    00000116
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecxf---

Explore more