← Back

CVE-2025-23184

nvd nist
Published: Jan 21, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).

Affected (3)

Products: Apache: Cxf
1 product
Cxf
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 3.5.10
From 3.6.0 to 3.6.5
From 4.0.0 to 4.0.6

References (5)

Timeline

No history available yet.