Allocation of Resources Without Limits or Throttling in Apache CXF - CVE-2026-57819
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource allocation in the JAX-RS form parameter processing in cxf-rt-frontend-jaxrs when handling requests with very large numbers of form parameters. A remote attacker can send a specially crafted request to cause a denial of service.
Affected software
IBM Tivoli Monitoring
How to mitigate CVE-2026-57819
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5