CVE-2026-57819: Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co
Summary
Apache CXF, a web services framework, has a vulnerability where it doesn't set a default limit on how many form parameters (data fields submitted in a web request) it will accept. This can allow attackers to send requests with extremely large numbers of parameters, causing a denial of service attack (making the service unavailable by overwhelming it with resource consumption).
Solution / Mitigation
Users are recommended to upgrade to versions 4.2.3, 4.1.8, or 3.6.12, which fix this issue by using a default limit of 500 parameters.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
network
low
none
none
August 6, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-57819
First tracked: August 6, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 72%