CVE-2026-44618
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.
An Improper Restriction of XML External Entity Reference vulnerability (CVE-2026-44618) has been identified in the WS-Transfer module of Apache CXF (org.apache.cxf:cxf-rt-ws-transfer), which allows attackers to perform XML external entity (XXE) attacks that disclose data by having the XML schema and XSLT processors used for WS-Transfer resources resolve external DTDs, schemas, and stylesheets.
Per OWASP, an XML External Entity (XXE) attack occurs when untrusted XML input that references an external entity is processed by a weakly configured XML parser. It can lead to file disclosure, server-side request forgery (SSRF), port scanning from the parser's host, and denial of service.
This issue affects versions before 3.6.11, 4.0.0 before 4.1.6, and 4.2.0 before 4.2.1 of Apache CXF.
Details
Module Info
- Product: Apache CXF
- Affected packages:
org.apache.cxf:cxf-rt-ws-transfer - Affected versions: <3.6.11, >=4.0.0 <4.1.6, >=4.2.0 <4.2.1
- GitHub repository: https://github.com/apache/cxf
- Published packages: https://central.sonatype.com/artifact/org.apache.cxf/cxf-rt-ws-transfer
- Package manager: Maven
- Fixed in:
- OSS Apache CXF 3.6.11, 4.1.6, 4.2.1
- NES for Apache CXF 3.5.11-cxf-3.5.13
Vulnerability Info
This Medium-severity vulnerability is found in the org.apache.cxf:cxf-rt-ws-transfer package in versions before 3.6.11, 4.0.0 before 4.1.6, and 4.2.0 before 4.2.1 of Apache CXF.
The WS-Transfer module lets a resource manager validate and transform incoming resource representations (for example on Create and Put requests) with an XML Schema (XSDResourceValidator, XSDResourceTypeIdentifier) and an XSLT stylesheet (XSLTResourceTransformer). Each of these classes builds its JAXP factory with default settings: secure processing is not enabled and access to external DTDs, schemas, and stylesheets is not restricted. The schema compilation, the validation of representation documents, and the stylesheet processing can therefore resolve external entities and fetch external resources, which lets an attacker read local files or cause the server to make requests to internal or external hosts (CWE-611).
In XSDResourceValidator (and identically in XSDResourceTypeIdentifier), the SchemaFactory is used unhardened:
public XSDResourceValidator(Source xsd, ResourceTransformer resourceTransformer) {
try {
SchemaFactory schemaFactory = SchemaFactory.newInstance(XMLConstants.W3C_XML_SCHEMA_NS_URI);
Schema schema = schemaFactory.newSchema(xsd);
this.validator = schema.newValidator();
} catch (SAXException ex) {
LOG.severe(ex.getLocalizedMessage());
throw new SoapFault("Internal error", getSoapVersion().getReceiver());
}
}
@Override
public boolean validate(Representation representation, Representation oldRepresentation) {
try {
validator.validate(new DOMSource((Node) representation.getAny()));
...
In XSLTResourceTransformer, the TransformerFactory is created with default settings and applied to the incoming representation:
public XSLTResourceTransformer(Source xsl, ResourceValidator validator) {
this.validator = validator;
try {
templates = TransformerFactory.newInstance().newTemplates(xsl);
} catch (TransformerConfigurationException e) {
LOG.severe(e.getLocalizedMessage());
throw new SoapFault("Internal error", getSoapVersion().getReceiver());
}
}
@Override
public ResourceValidator transform(Representation newRepresentation, Representation oldRepresentation) {
Document doc = DOMUtils.createDocument();
Node representation = (Node) newRepresentation.getAny();
Node importedNode = doc.importNode(representation, true);
doc.appendChild(importedNode);
Document result = XSLTUtils.transform(templates, doc);
newRepresentation.setAny(result.getDocumentElement());
return validator;
}
This vulnerability was introduced in 2017 with Apache CXF 3.2.0.
Mitigation
Only recent versions of Apache CXF are community-supported. The 3.5.x line was already End-of-Life when this CVE was published and will not receive public updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- IcySun from Guangdong Dongfang Siwei Technology Co., Ltd. (finder)