CVE-2026-49875

CRITICAL WAF: High
CVSS 9.8 Published: 2026-06-12
CWE-611

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
apachecxfup to 4.1.7
apachecxf4.2.0 - 4.2.2

References

Back to CVE Database