Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66909

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

A flaw was found in Apache CXF. The Java Message Service (JMS) transport component improperly deserializes inbound JMS ObjectMessages without type restrictions. A remote attacker can exploit this by sending a specially crafted message to the service's JMS destination. This vulnerability could lead to a denial of service or, in certain configurations, enable remote code execution on the affected system.

Отчет

This vulnerability in Apache CXF's JMS transport is rated as Important because it allows for remote code execution or denial of service if an attacker can send a specially crafted JMS ObjectMessage to a service. This is particularly relevant in Red Hat environments where Apache CXF is used in applications that process JMS messages, as the default deserialization behavior without type restrictions increases the attack surface. Exploitation requires the presence of a suitable gadget class on the classpath.

Меры по смягчению последствий

To mitigate this vulnerability, disable ObjectMessage deserialization in Apache CXF's JMS transport. This can typically be achieved through a configuration setting provided by the Apache CXF framework. Consult the Apache CXF documentation for specific instructions on how to disable ObjectMessage deserialization in your deployment. Disabling this feature may impact applications that rely on ObjectMessage for legitimate data transfer.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4cxf-rt-transports-jmsAffected
Red Hat JBoss Enterprise Application Platform 7cxfAffected
Red Hat JBoss Enterprise Application Platform 7cxf-rt-transports-jmsAffected
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk11-openshift-rhel8/eap74-els-openjdk11-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk17-openshift-rhel8/eap74-els-openjdk17-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7eap74-els-openjdk8-openshift-rhel8/eap74-els-openjdk8-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7-eap74-els-openjdk17-openshift-rhel8/jboss-eap-7-eap74-els-openjdk17-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7-eap74-els-openjdk8-openshift-rhel8/jboss-eap-7-eap74-els-openjdk8-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 8cxf-rt-transports-jmsAffected
Red Hat JBoss Enterprise Application Platform Expansion Packcxf-rt-transports-jmsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2511983org.apache.cxf/cxf: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage

EPSS

Процентиль: 50%
0.00667
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

CVSS3: 9.8
github
около 2 месяцев назад

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

EPSS

Процентиль: 50%
0.00667
Низкий

8.1 High

CVSS3