Published on October 9, 2026 by Colm O hEigeartaigh on the oss-sec feed, advisory CVE-2026-108039 concerns Apache CXF. The stated severity is low. According to the text, by default StaxUtils did not impose limits on the total number of elements or the total number of characters in an XML document. As a result, a very large request could consume a lot of memory and CPU during parsing, especially when CXF builds a DOM from the input, for example in SAAJ or WS-Security. The listed affected versions are: Apache CXF 4.2.0 up to before 4.2.4; 4.0.0 up to before 4.1.9; and anything before 3.6.13. The available excerpt is an automatic translation and ends before describing the full impact, so consult the original source for the complete picture and the fixes. Relevance: this is an advisory about a Java web services library, not about the Rota Nacional platform. The material does not state that Rota or its services use this library, and this bulletin does not claim any fix made by Rota. If you use AI to study the advisory, do not paste logs, server names, credentials or personal data into the prompt. Remove those elements first.
Cyber ·
CVE-2026-108039: Apache CXF limits XML elements and characters in StaxUtils
Low-severity advisory on missing limits in Apache CXF StaxUtils, which can consume memory and CPU when parsing very large XML documents. Versions 3.6, 4.0 and 4.2 are listed as affected.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.