Skip to main content

CVE-2026-78384: Vulnerability in Apache Software Foundation Apache CXF

0
High
VulnerabilityCVE-2026-78384cvecve-2026-78384
Published: 10/09/2026 (10/09/2026, 10:18:00 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache CXF

Description

CompressionUtils.inflate() decompressed attacker-controlled DEFLATE data with no output-size cap. A small (~KB) crafted payload could expand to gigabytes on the heap. Reachable via JWE decryption when zip=DEF (e.g. JoseSessionTokenProvider with RSA-OAEP key wrap) and via SAML redirect/POST binding token inflation — in both cases decompression happens before/independent of trust validation. Fix: Added a configurable maximum inflated-size cap (default 10 MiB, org.apache.cxf.compression-max-inflated-size system property) to CompressionUtils.inflate(); aborts with DataFormatException once exceeded. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Affected software

Apache Software Foundation

Apache CXF

Affected versions
>=4.2.0 <4.2.4>=4.0.0 <4.1.9>=0 <3.6.13
Apache Software Foundation/org.apache.cxf:cxf-core
pkg:maven/Apache Software Foundation/org.apache.cxf:cxf-core
Affected versions
>=4.2.0 <4.2.4>=4.0.0 <4.1.9>=0 <3.6.13

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 10:49:14 UTC

Technical Analysis

The Apache CXF library's CompressionUtils.inflate() function previously decompressed DEFLATE-compressed data without limiting the maximum output size. An attacker can supply a crafted compressed payload that is small in size but expands to gigabytes in memory during decompression, leading to potential denial of service via resource exhaustion. This vulnerability is exploitable through JWE decryption when the compression method is set to DEFLATE (zip=DEF), such as in the JoseSessionTokenProvider with RSA-OAEP key wrap, and also through SAML redirect or POST binding token inflation. The decompression occurs before or independent of any trust validation, increasing risk. The Apache Software Foundation fixed this by introducing a configurable maximum inflated size cap (default 10 MiB) in CompressionUtils.inflate(), which throws a DataFormatException if exceeded. The fix is included in Apache CXF versions 4.2.4, 4.1.9, and 3.6.13.

Potential Impact

An attacker can cause excessive memory consumption by sending a small compressed payload that decompresses to a very large size, potentially leading to denial of service conditions such as application crashes or resource exhaustion. This occurs before any trust validation, so malicious payloads can trigger the vulnerability without authentication or authorization.

Mitigation Recommendations

A fix is available and users are strongly recommended to upgrade to Apache CXF versions 4.2.4, 4.1.9, or 3.6.13 or later. The fix adds a configurable maximum inflated size cap to prevent decompression of excessively large data. No additional mitigation is required if these versions are deployed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-24T13:44:56.686Z
State
PUBLISHED

Threat ID: 6ac8c31f2cdf04f6564c0cd8

Added to database: 10/09/2026, 10:34:07 UTC

Last enriched: 10/09/2026, 10:49:14 UTC

Last updated: 10/09/2026, 18:57:32 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses