Skip to content
VulniPulse
Highest advisory severityUnrated 1 vendor · 1 advisory

CVE-2026-86463

CVE-2026-86463: 1 tracked advisory record across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

1 advisory
  • Advisory severityUnrated

    Advisory [CVE-2026-86463] Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions

    CVE-2026-86463Source published Source updated

    Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions. The search pattern can get stuck trying many combinations when it encounters a long string without an operator, causing the parser to consume excessive CPU time. An attacker can send a crafted query to make the server use up CPU resources, potentially slowing down or stopping other requests. The fix was to limit FIQL expressions to 4 KiB by default, preventing attackers from sending extremely long inputs while still allowing normal queries. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

    Related products — impact not confirmed
    • Apache CXF
    Source-reported affected versions
    • Apache CXF 4.2.0 before 4.2.4
    • Apache CXF 4.0.0 before 4.1.9
    • Apache CXF before 3.6.13
    Source-reported fixed versions
    • 4.2.4
    • 4.1.9
    • 3.6.13
    Mitigation guidance
    • The fix was to limit FIQL expressions to 4 KiB by default, preventing attackers from sending extremely long inputs while still allowing normal queries.
    • Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery