Known vulnerabilities in Apache Foundation Apache CXF
4.1.3
4.0.9
3.6.8
4.1.2
4.0.8
3.6.7
4.1.1
4.0.7
3.6.6
3.5.11
4.1.0
4.0.6
3.6.5
3.5.10
4.0.5
3.6.4
3.5.9
3.6.3
3.5.8
4.0.4
4.0.3
3.6.2
3.5.7
4.0.2
3.6.1
4.0.1
3.6.0
3.5.6
4.0.0
3.5.5
3.4.10
3.5.4
3.4.9
3.5.3
3.4.8
3.5.2
3.4.7
3.5.1
3.4.6
3.3.13
3.5.0
3.4.5
3.3.12
3.4.4
3.3.11
3.4.3
3.3.10
3.4.2
3.3.9
3.4.1
3.3.8
3.4.0
3.3.7
3.2.14
3.2.13
3.3.6
3.3.5
3.2.12
3.3.4
3.3.3
3.3.2
3.3.1
3.3.0
3.2.11
3.2.10
3.2.9
3.2.8
3.2.7
3.2.6
3.1.18
3.1.17
3.0.16
3.0.15
3.0.14
3.0.13
3.0.12
3.0.11
3.0.10
3.0.9
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.7.18
2.7.17
2.7.16
2.7.15
2.7.14
2.7.13
2.7.12
2.7.11
2.7.10
2.7.9
2.7.8
2.7.7
2.7.6
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
2.6.17
2.6.16
2.6.15
2.6.14
2.6.13
2.6.12
2.6.11
2.6.10
2.6.9
2.6.8
2.6.7
2.6.6
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.11
2.5.10
2.5.9
2.5.8
2.5.7
2.5.6
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.10
2.4.9
2.4.8
2.4.7
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.11
2.3.10
2.3.9
2.3.8
2.3.7
2.3.6
2.3.5
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.12
2.2.11
2.2.10
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1
2.0.13
2.0.12
2.0.11
2.0.10
2.0.9
2.0.8
2.0.7
2.0.6
2.7.5
3.2.5
3.1.16
3.2.4
3.2.3
3.2.2
3.1.15
3.1.14
3.2.1
3.1.13
3.1.12
3.1.11
3.1.10
3.1.9
3.1.8
3.1.7
3.1.6
3.1.5
3.1.4
3.1.3
3.1.2
3.1.1
3.1.0
3.2.0
Security bulletins (13)
| Secuity bulletin | Severity | Status | Published |
|---|---|---|---|
| SB2025101733: Remote code execution in Apache CXF | Medium | 17.10.2025 | |
| SB2025022807: Denial of service in Apache CXF | Medium | 28.02.2025 | |
| SB2024091810: Multiple vulnerabilities in Apache CXF | Medium | 18.09.2024 | |
| SB2024031529: SSRF in Apache CXF | Medium | 15.03.2024 | |
| SB2022122009: Multiple vulnerabilities in Apache CXF | Medium | 20.12.2022 | |
| SB2021082016: Denial of service in Apache CXF | Medium | 20.08.2021 | |
| SB2021040608: Denial of service in Apache CXF | Medium | 06.04.2021 | |
| SB2020040206: Man-in-the-Middle (MitM) attack in Apache CXF | Low | 02.04.2020 | |
| SB2020012013: Cross-site scripting in Apache CXF | Low | 20.01.2020 | |
| SB2020011628: Information disclosure in Apache CXF | Medium | 16.01.2020 | |
| SB2019110708: Multiple vulnerabilities in Apache CXF | Medium | 07.11.2019 | |
| SB2018062910: Man-in-the-middle attack in Apache CXF | Low | 29.06.2018 | |
| SB2017111431: Denial of service in Apache CXF | Low | 14.11.2017 |