Skip to content
Rota Nacional

Cyber ·

CVE-2026-107937: Apache CXF attachment header limits can be bypassed, causing denial of service

Low-severity advisory on Apache CXF: the multipart/MTOM attachment header parser did not fully enforce configured limits, which can lead to memory exhaustion. Fixed versions: 4.2.4, 4.1.9 and 3.6.13.

Fact: advisory CVE-2026-107937, posted to the oss-sec list on 9 October 2026 and rated low severity, describes a flaw in Apache CXF. The parser for multipart/MTOM attachment part headers did not fully enforce the configured limits: attachment-max-header-size, default 300 characters, and attachment-headers-max-count, default 500. According to the description, the size limit was applied only to each physical line, not to a header value formed from continued lines. The stated effect is denial of service through memory exhaustion.

Affected versions: Apache CXF 4.2.0 before 4.2.4; 4.0.0 before 4.1.9; and any version before 3.6.13.

Relevance: Rota Nacional does not provide or fix the Apache CXF library. Organizations running Java services with this dependency, especially those receiving MTOM or multipart attachments from external sources, should check the version in use and upgrade to a fixed release. Rota Nacional does not claim to solve this engineering problem.

To consult and verify: read the original advisory on the oss-sec list and the Apache CXF project's version documentation, confirming the versions and severity stated.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free