CVE-2025-23184 Details
Description
A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).
A denial-of-service vulnerability has been identified in Apache CXF versions prior to 3.5.10, 3.6.0 prior to 3.6.5, and 4.0.0 prior to 4.0.6. In certain edge cases, instances of CachedOutputStream may not be properly closed. If these instances are backed by temporary files, they can accumulate and potentially fill up the file system, affecting both server and client environments.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache cxf | < 3.5.10 >= 3.6.0, < 3.6.5 >= 4.0.0, < 4.0.6 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 15, 2025 | CVE Modified | CVE |
| Feb 15, 2025 | CVE Modified | CVE |
| Feb 11, 2025 | Initial Analysis | [email protected] |
| Jan 21, 2025 | New CVE Received | [email protected] |
| Jan 21, 2025 | CVE Modified | CVE |