CVE-2026-107937

CVE-2026-107937 published: In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each phys...

View full NVD advisory → ← Back to CVE watch