CVE-2026-107937 Apache CXF 多部分附件头解析拒绝服务漏洞
影响远程未认证攻击者可耗尽服务器内存导致拒绝服务
Apache CXF 在处理 multipart/MTOM 附件头时未完整执行配置的 attachment-max-header-size 与 attachment-headers-max-count 限制。大小限制仅作用于单个物理行,未覆盖续行拼接后的头值或重复头的合并值;数量限制按不同头名称计数而非头行总数。攻击者可发送包含超大折叠或重复头的 multipart 请求,使服务器无界分配内存,造成拒绝服务。
影响范围
Apache CXF 受影响版本范围暂无公开的完整列表,官方建议升级至 4.2.4、4.1.9 或 3.6.13 以修复该问题。
漏洞详情
该漏洞属于资源耗尽型拒绝服务。成因是解析器对 multipart/MTOM 附件头的长度与数量校验不完整:长度校验只针对每一物理行,未对续行拼接结果或重复头合并值生效;数量校验统计的是不同头名称数而非头行总数。利用方式是远程未认证攻击者构造带有超长折叠头或大量重复头的 multipart 请求,触发服务器无界内存分配。
利用条件与风险
利用无需认证,攻击者只需能向暴露的 CXF 服务发送 multipart 请求即可触发,实战中可造成服务不可用。
修复建议
官方修复方案为升级至 4.2.4、4.1.9 或 3.6.13。临时缓解措施暂无公开信息,可考虑在网关层限制 multipart 请求体大小与头数量。
In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.