oss-sec mailing list archives

CVE-2024-41172: Unrestricted memory consumption in CXF HTTP clients


From: Colm O hEigeartaigh <coheigea () apache org>
Date: Thu, 18 Jul 2024 16:52:29 +0100

CVE-2024-41172: Unrestricted memory consumption in CXF HTTP clients

Severity: low

Affected versions:

- Apache CXF 3.6.0, 4.0.0 before 3.6.4, 4.0.5

Description:

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower
versions are not impacted), a CXF HTTP client conduit may prevent
HTTPClient instances from being garbage collected and it is possible
that memory consumption will continue to increase, eventually causing
the application to run  out of memory

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-41172


Current thread: