Skip to content
Rota Nacional

Cyber ·

CVE-2026-86463: denial of service in the Apache CXF FIQL query parser

A low-severity flaw in the Apache CXF FIQL query parser, disclosed on 9 October 2026, can cause denial of service in specific version ranges.

CVE-2026-86463 describes a denial of service in the FIQL query parser of Apache CXF. According to the advisory posted by Colm O hEigeartaigh on the oss-sec list on 9 October 2026, the parser can try many combinations while searching for operators in query expressions, and the search pattern can get stuck in that process. The stated severity is low. The affected module is org.apache.cxf:cxf-rt-rs-extension-search in the ranges 4.2.0 before 4.2.4, 4.0.0 before 4.1.9, and versions before 3.6.13. The text available in the feed is a machine translation. To verify, consult the original advisory on the oss-sec list and the Apache CXF fix notes, and confirm the exact version used in your environment.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free