天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-108039 Apache CXF StaxUtils XML 解析拒绝服务漏洞

影响攻击者可通过超大 XML 请求耗尽内存与 CPU,导致服务拒绝

MEDIUM
暂无 CVSS 评分
AI 研判

Apache CXF 的 StaxUtils 默认未限制 XML 文档的元素总数和字符总数。当处理超大请求时,解析过程会消耗大量内存和 CPU,尤其在 CXF 构建 DOM(如 SAAJ 或 WS-Security)的场景下,可能造成拒绝服务。

影响范围

Apache CXF

受影响组件为 Apache CXF 的 StaxUtils。官方建议升级至 4.2.4、4.1.9 或 3.6.13 版本以修复该问题;更早的具体受影响版本范围暂无公开信息。

漏洞详情

该漏洞属于资源耗尽型拒绝服务(DoS)。成因是 StaxUtils 默认对 XML 文档的元素数量和字符数量没有上限,攻击者只需发送超大 XML 请求即可在解析阶段占用大量内存和 CPU。当应用未配置请求大小限制时,服务可能因资源耗尽而不可用。

利用条件与风险

利用前提是目标应用使用存在缺陷的 CXF 版本解析外部可控的 XML 输入,且未配置请求大小限制。实战中可被用于远程拒绝服务攻击,风险取决于服务暴露程度与输入可控性。

修复建议

官方修复方案为升级至 4.2.4、4.1.9 或 3.6.13 版本。临时缓解措施包括在应用层限制请求体大小,或通过 org.apache.cxf.stax.maxElementCount 和 org.apache.cxf.stax.maxXMLCharacters 属性调整解析上限。

原始情报

By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or WS-Security), and could cause a denial of service when no request size limit was configured. Both limits now have defaults: the maximum element count is 100 × maxChildElements (5,000,000 by default), and the maximum document size is 256M characters. Applications that process larger documents can raise the limits with the org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters properties.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.