PT-2026-48844 · Apache · Apache Cxf

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-49875

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-49875

Affected Products

Apache Cxf