CVE-2025-23184

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-21 10:15

Updated : 2025-02-15 01:15


NVD link : CVE-2025-23184

Mitre link : CVE-2025-23184

CVE.ORG link : CVE-2025-23184


JSON object : View

Products Affected

apache

  • cxf
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo