天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-107937 Apache CXF 多部分附件头解析拒绝服务漏洞

影响远程未认证攻击者可耗尽服务器内存导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Apache CXF 在处理 multipart/MTOM 附件头时未完整执行配置的 attachment-max-header-size 与 attachment-headers-max-count 限制。大小限制仅作用于单个物理行,未覆盖续行拼接后的头值或重复头的合并值;数量限制按不同头名称计数而非头行总数。攻击者可发送包含超大折叠或重复头的 multipart 请求,使服务器无界分配内存,造成拒绝服务。

影响范围

Apache CXF

Apache CXF 受影响版本范围暂无公开的完整列表,官方建议升级至 4.2.4、4.1.9 或 3.6.13 以修复该问题。

漏洞详情

该漏洞属于资源耗尽型拒绝服务。成因是解析器对 multipart/MTOM 附件头的长度与数量校验不完整:长度校验只针对每一物理行,未对续行拼接结果或重复头合并值生效;数量校验统计的是不同头名称数而非头行总数。利用方式是远程未认证攻击者构造带有超长折叠头或大量重复头的 multipart 请求,触发服务器无界内存分配。

利用条件与风险

利用无需认证,攻击者只需能向暴露的 CXF 服务发送 multipart 请求即可触发,实战中可造成服务不可用。

修复建议

官方修复方案为升级至 4.2.4、4.1.9 或 3.6.13。临时缓解措施暂无公开信息,可考虑在网关层限制 multipart 请求体大小与头数量。

原始情报

In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service. 
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.