CVE-2026-64958
CVE-2026-64958: 2 tracked advisory records across Apache, NetApp. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh7.5
High [CVE-2026-50645 +1] incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers
CVE-2026-64958Source published Source updated
This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
- Affected products in this advisory
- Apache CXF
- Source-reported affected versions
- Apache CXF 4.2.0 before 4.2.3
- Apache CXF 4.0.0 before 4.1.8
- Apache CXF before 3.6.12
- Source-reported fixed versions
- 4.2.3
- 4.1.8
- 3.6.12
- Mitigation guidance
- Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
NetApp
1 advisory- Advisory severityHigh7.5
High [CVE-2026-64958] Apache CXF Vulnerability in NetApp Products
NTAP-20260911-0010Source published Source updated
Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.78 and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: SnapCenter. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- SnapCenter
- Source-reported affected versions
- 3.6.12
- 4.0.0
- 4.1.78
- 4.2.0
1 more entries in the full advisory.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.