Cxf
Vendor:
First CVE: Aug 19, 2010 · Active for 15 years
57
Total CVEs
More Total CVEs than 98% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cxf over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2010
15 years ago
Most Recent CVE
Jun 12, 2026
42 days ago
CVE Severity & Scoring
Cxf57 CVEs
49%
32%
19%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network40 (70.2%)
Unknown15 (26.3%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low36 (63.2%)
High6 (10.5%)
Unknown15 (26.3%)
User Interaction
None36 (63.2%)
Unknown15 (26.3%)
Required6 (10.5%)
Privileges Required
Low2 (3.5%)
High1 (1.8%)
None39 (68.4%)
Unknown15 (26.3%)
Top CVEs
Signals from CVEs in this product scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28752CRITICAL A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take a | Mar 15, 2024 | 9.3 | 44 | NO | YES |
CVE-2026-44930CRITICAL An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
U | May 22, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-50628CRITICAL A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
sec | Jun 12, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-49875CRITICAL Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
| Jun 12, 2026 | 9.8 | 40 | NO | NO |
CVE-2020-13954MEDIUM By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting ( | Nov 12, 2020 | 6.1 | 38 | NO | NO |
CVE-2013-2160MEDIUM The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumpt | Aug 19, 2013 | 5.0 | 38 | NO | YES |
CVE-2026-50632HIGH A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution cap | Jun 12, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-50627CRITICAL The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be | Jun 12, 2026 | 9.1 | 37 | NO | NO |
CVE-2019-12419CRITICAL Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token se | Nov 6, 2019 | 9.8 | 37 | NO | NO |
CVE-2026-50633HIGH A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployme | Jun 12, 2026 | 8.1 | 36 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (57 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.8% of CVEs· 96th percentile
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (57 CVEs).
Media Mentions
Signals from CVEs in this product scope (57 CVEs).
Top CNAs Publishing CVEs For Cxf
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.2.0 | 3 | 7.5 | 0.6% | 0 | 0 |
| 4.1.0 | 1 | 5.6 | 0.6% | 0 | 0 |
| 4.0.6 | 1 | 5.6 | 0.6% | 0 | 0 |
| 3.6.5 | 1 | 5.6 | 0.6% | 0 | 0 |
| 3.5.10 | 1 | 5.6 | 0.6% | 0 | 0 |
| 3.4.4 | 1 | 7.5 | 7.4% | 0 | 0 |
| 3.1.9 | 1 | 7.5 | 6.3% | 0 | 0 |
| 3.1.8 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.7 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.6 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.5 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.4 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.3 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.2 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.1 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.1.0 | 3 | 7.0 | 7.6% | 0 | 0 |
| 3.0.0 | 1 | 5.0 | 7.2% | 0 | 0 |
| 2.7.9 | 3 | 4.3 | 4.8% | 0 | 0 |
| 2.7.8 | 4 | 4.3 | 5.4% | 0 | 0 |
| 2.7.7 | 5 | 4.4 | 5.8% | 0 | 0 |