Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-108039

CVE-2026-108039: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityUnrated

    Advisory [CVE-2026-108039] By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document

    CVE-2026-108039Source published Source updated

    By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or WS-Security), and could cause a denial of service when no request size limit was configured. Both limits now have defaults: the maximum element count is 100 × maxChildElements (5,000,000 by default), and the maximum document size is 256M characters. Applications that process larger documents can raise the limits with the org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters properties. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

    Related products — impact not confirmed
    • Apache CXF
    Source-reported affected versions
    • Apache CXF 4.2.0 before 4.2.4
    • Apache CXF 4.0.0 before 4.1.9
    • Apache CXF before 3.6.13
    Source-reported fixed versions
    • 4.2.4
    • 4.1.9
    • 3.6.13
    Mitigation guidance
    • By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document.
    • A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or WS-Security), and could cause a denial of service when no request size limit was configured.
    • Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-108039] Denial of Service via unrestricted XML parsing

    CVE-2026-108039Source published Source updated

    Denial of Service via unrestricted XML parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 4 more.

    Related products — impact not confirmed
    • Red Hat build of Apache Camel 4 for Quarkus 3
    • Red Hat build of Apache Camel for Spring Boot 4
    • Red Hat Fuse 7
    • Red Hat JBoss Enterprise Application Platform 7

    4 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery