CVE-2026-44618

Improper Restriction of XML External Entity Reference
Affects
cxf-rt-ws-transfer
in
Apache CXF
No items found.
Versions
<3.6.11, >=4.0.0 <4.1.6, >=4.2.0 <4.2.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

An Improper Restriction of XML External Entity Reference vulnerability (CVE-2026-44618) has been identified in the WS-Transfer module of Apache CXF (org.apache.cxf:cxf-rt-ws-transfer), which allows attackers to perform XML external entity (XXE) attacks that disclose data by having the XML schema and XSLT processors used for WS-Transfer resources resolve external DTDs, schemas, and stylesheets.

Per OWASP, an XML External Entity (XXE) attack occurs when untrusted XML input that references an external entity is processed by a weakly configured XML parser. It can lead to file disclosure, server-side request forgery (SSRF), port scanning from the parser's host, and denial of service.

This issue affects versions before 3.6.11, 4.0.0 before 4.1.6, and 4.2.0 before 4.2.1 of Apache CXF.

Details

Module Info

Vulnerability Info

This Medium-severity vulnerability is found in the org.apache.cxf:cxf-rt-ws-transfer package in versions before 3.6.11, 4.0.0 before 4.1.6, and 4.2.0 before 4.2.1 of Apache CXF.

The WS-Transfer module lets a resource manager validate and transform incoming resource representations (for example on Create and Put requests) with an XML Schema (XSDResourceValidator, XSDResourceTypeIdentifier) and an XSLT stylesheet (XSLTResourceTransformer). Each of these classes builds its JAXP factory with default settings: secure processing is not enabled and access to external DTDs, schemas, and stylesheets is not restricted. The schema compilation, the validation of representation documents, and the stylesheet processing can therefore resolve external entities and fetch external resources, which lets an attacker read local files or cause the server to make requests to internal or external hosts (CWE-611).

In XSDResourceValidator (and identically in XSDResourceTypeIdentifier), the SchemaFactory is used unhardened:

public XSDResourceValidator(Source xsd, ResourceTransformer resourceTransformer) {
    try {
        SchemaFactory schemaFactory = SchemaFactory.newInstance(XMLConstants.W3C_XML_SCHEMA_NS_URI);
        Schema schema = schemaFactory.newSchema(xsd);
        this.validator = schema.newValidator();
    } catch (SAXException ex) {
        LOG.severe(ex.getLocalizedMessage());
        throw new SoapFault("Internal error", getSoapVersion().getReceiver());
    }
}

@Override
public boolean validate(Representation representation, Representation oldRepresentation) {
    try {
        validator.validate(new DOMSource((Node) representation.getAny()));
    ...

In XSLTResourceTransformer, the TransformerFactory is created with default settings and applied to the incoming representation:

public XSLTResourceTransformer(Source xsl, ResourceValidator validator) {
    this.validator = validator;
    try {
        templates = TransformerFactory.newInstance().newTemplates(xsl);
    } catch (TransformerConfigurationException e) {
        LOG.severe(e.getLocalizedMessage());
        throw new SoapFault("Internal error", getSoapVersion().getReceiver());
    }
}

@Override
public ResourceValidator transform(Representation newRepresentation, Representation oldRepresentation) {
    Document doc = DOMUtils.createDocument();
    Node representation = (Node) newRepresentation.getAny();
    Node importedNode = doc.importNode(representation, true);
    doc.appendChild(importedNode);
    Document result = XSLTUtils.transform(templates, doc);
    newRepresentation.setAny(result.getDocumentElement());
    return validator;
}

This vulnerability was introduced in 2017 with Apache CXF 3.2.0.

Mitigation

Only recent versions of Apache CXF are community-supported. The 3.5.x line was already End-of-Life when this CVE was published and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • IcySun from Guangdong Dongfang Siwei Technology Co., Ltd. (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2026-44618
PROJECT Affected
cxf-rt-ws-transfer
Versions Affected
<3.6.11, >=4.0.0 <4.1.6, >=4.2.0 <4.2.1
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
September 29, 2026
Category
Improper Restriction of XML External Entity Reference
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.