Allocation of Resources Without Limits or Throttling in Apache CXF - CVE-2026-54225
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource control in attachment processing when handling large attachments without a configured maximum attachment size. A remote attacker can send a specially crafted request with a large attachment to cause a denial of service.
Only deployments that do not explicitly configure an attachment size limit are vulnerable.
Affected software
IBM Tivoli Monitoring
How to mitigate CVE-2026-54225
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5