CVE-2026-78384: Vulnerability in Apache Software Foundation Apache CXF
Description
CompressionUtils.inflate() decompressed attacker-controlled DEFLATE data with no output-size cap. A small (~KB) crafted payload could expand to gigabytes on the heap. Reachable via JWE decryption when zip=DEF (e.g. JoseSessionTokenProvider with RSA-OAEP key wrap) and via SAML redirect/POST binding token inflation — in both cases decompression happens before/independent of trust validation. Fix: Added a configurable maximum inflated-size cap (default 10 MiB, org.apache.cxf.compression-max-inflated-size system property) to CompressionUtils.inflate(); aborts with DataFormatException once exceeded. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Affected software
Apache Software Foundation
Apache CXF
pkg:maven/Apache Software Foundation/org.apache.cxf:cxf-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Apache CXF library's CompressionUtils.inflate() function previously decompressed DEFLATE-compressed data without limiting the maximum output size. An attacker can supply a crafted compressed payload that is small in size but expands to gigabytes in memory during decompression, leading to potential denial of service via resource exhaustion. This vulnerability is exploitable through JWE decryption when the compression method is set to DEFLATE (zip=DEF), such as in the JoseSessionTokenProvider with RSA-OAEP key wrap, and also through SAML redirect or POST binding token inflation. The decompression occurs before or independent of any trust validation, increasing risk. The Apache Software Foundation fixed this by introducing a configurable maximum inflated size cap (default 10 MiB) in CompressionUtils.inflate(), which throws a DataFormatException if exceeded. The fix is included in Apache CXF versions 4.2.4, 4.1.9, and 3.6.13.
Potential Impact
An attacker can cause excessive memory consumption by sending a small compressed payload that decompresses to a very large size, potentially leading to denial of service conditions such as application crashes or resource exhaustion. This occurs before any trust validation, so malicious payloads can trigger the vulnerability without authentication or authorization.
Mitigation Recommendations
A fix is available and users are strongly recommended to upgrade to Apache CXF versions 4.2.4, 4.1.9, or 3.6.13 or later. The fix adds a configurable maximum inflated size cap to prevent decompression of excessively large data. No additional mitigation is required if these versions are deployed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-24T13:44:56.686Z
- State
- PUBLISHED
Threat ID: 6ac8c31f2cdf04f6564c0cd8
Added to database: 10/09/2026, 10:34:07 UTC
Last enriched: 10/09/2026, 10:49:14 UTC
Last updated: 10/09/2026, 18:57:32 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.