GHSA-vmm5-fjgx-2jhp

Suggest an improvement
Source
https://github.com/advisories/GHSA-vmm5-fjgx-2jhp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vmm5-fjgx-2jhp/GHSA-vmm5-fjgx-2jhp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vmm5-fjgx-2jhp
Aliases
Published
2026-05-26T13:30:15Z
Modified
2026-06-29T23:26:32Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Apache CXF's WS-Transfer module has an insecure XML parser configuration
Details

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-611"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-29T23:01:34Z",
    "nvd_published_at":  "2026-05-22T13:16:22Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.apache.cxf:cxf-rt-ws-transfer

Package

Name
org.apache.cxf:cxf-rt-ws-transfer
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf/cxf-rt-ws-transfer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.2.1

Affected versions

4.*
4.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vmm5-fjgx-2jhp/GHSA-vmm5-fjgx-2jhp.json"

Maven / org.apache.cxf:cxf-rt-ws-transfer

Package

Name
org.apache.cxf:cxf-rt-ws-transfer
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf/cxf-rt-ws-transfer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Fixed
4.1.6

Affected versions

4.*
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vmm5-fjgx-2jhp/GHSA-vmm5-fjgx-2jhp.json"

Maven / org.apache.cxf:cxf-rt-ws-transfer

Package

Name
org.apache.cxf:cxf-rt-ws-transfer
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf/cxf-rt-ws-transfer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.11

Affected versions

3.*
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.2.10
3.2.11
3.2.12
3.2.13
3.2.14
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.3.10
3.3.11
3.3.12
3.3.13
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.10
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.5.10
3.5.11
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.6.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vmm5-fjgx-2jhp/GHSA-vmm5-fjgx-2jhp.json"