CVE-2024-41172: Apache CXF: Unrestricted memory consumption in CXF HTTP clients
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41172?
CVE-2024-41172 has been classified as a medium severity denial of service vulnerability.
How do I fix CVE-2024-41172?
To fix CVE-2024-41172, upgrade your Apache CXF installation to version 3.6.4 or higher, or to version 4.0.5 or higher.
Which versions of Apache CXF are affected by CVE-2024-41172?
CVE-2024-41172 affects Apache CXF versions between 3.6.0 and 3.6.4, and between 4.0.0 and 4.0.5.
Can CVE-2024-41172 be exploited remotely?
Yes, CVE-2024-41172 can be exploited remotely by sending specially crafted HTTP requests.
What impact does CVE-2024-41172 have on affected systems?
CVE-2024-41172 can lead to denial of service by preventing HTTPClient instances from being garbage collected, consuming significant memory.