Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-2076

30
FAUCET Score

CVE-2010-2076 describes a critical vulnerability in Apache CXF versions 2.0.x, 2.1.x, and 2.2.x, impacting products like Apache ServiceMix and Apache Camel. This flaw allows remote attackers to exploit improper DTD rejection in SOAP messages, leading to arbitrary file reading, intranet server requests, or denial of service through CPU and memory exhaustion. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, enabling full compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, its high FAUCET Risk Score of 90/100 indicates a severe potential threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.6, < 2.0.13CPE matchmatch criteria
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
>= 2.1, < 2.1.10CPE matchmatch criteria
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
>= 2.2.0, < 2.2.9CPE matchmatch criteria
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
9.79%
Probability of exploitation in next 30 days
EPSS Percentile
95.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0979 is in the 91st percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.apache.cxf:cxf-rt-frontend-jaxrsFixed in: 2.0.13
mavenpatch availablevia ghsa
Product: org.apache.cxf:cxf-rt-frontend-jaxrsFixed in: 2.1.10
mavenpatch availablevia ghsa
Product: org.apache.cxf:cxf-rt-frontend-jaxrsFixed in: 2.2.9

Vendor Advisories (2)

mavenGHSA-v8q2-94f6-6xq2high

Improper Input Validation in Apache CXF

May 13, 2022
redhatCVE-2010-2076Important

CXF: Insufficient constraints on Document Type Declarations (DTDs)

Jun 15, 2010

References

geronimo.apache.org / 2010/07/21/apache-geronimo-v216-released.html
Vendor Advisory
geronimo.apache.org / 21x-security-report.html
Release NotesVendor Advisory
geronimo.apache.org / 22x-security-report.html
Release NotesVendor Advisory
secunia.com / advisories/40969
Broken LinkVendor Advisory
secunia.com / advisories/41016
Broken LinkVendor Advisory
secunia.com / advisories/41025
Broken LinkVendor Advisory
issues.apache.org / jira/browse/GERONIMO-5383
Third Party Advisory
lists.apache.org / thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
Mailing ListPatch
svn.apache.org / repos/asf/cxf/trunk/security/CVE-2010-2076.pdf
ExploitVendor Advisory
listware.net / 201006/cxf-users/60160-important-apache-cxf-security-advisory-cve-2010-2076.html
Broken Link
securityfocus.com / bid/42492
Broken LinkThird Party AdvisoryVDB Entry