← back
CVE-2025-23184

Apache CXF: Denial of Service vulnerability with temporary files

CVSS 5.9 MEDIUMEPSS 1.9%CWE-400
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 1.9%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
21 Jan 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →