---
id: CVE-2026-107937
title: >-
  In Apache CXF, the parser for multipart/MTOM attachment part headers did not
  fully enforce the configured attachment-max-header-size (default 300
  characters) and attachment-headers-max-count (default 500) limits
summary: >-
  In Apache CXF, the parser for multipart/MTOM attachment part headers did not
  fully enforce the configured attachment-max-header-size (default 300
  characters) and attachment-headers-max-count (default 500) limits. The size
  limit was appli…
severity: high
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T16:33:39.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107937'
references:
  - url: 'https://lists.apache.org/thread.html/x9twtpv3d04qj83t6w9xkh9y2q28zztj'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/09/12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-107937.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-107937'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2548463'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-107937'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107937'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-10-09T12:53:29.299Z'
vendor: Red Hat
product: Red Hat JBoss Enterprise Application Platform 7
affected:
  - build_of_apache_camel_4_for_quarkus 3
  - build_of_apache_camel_for_spring_boot 4
  - fuse 7
  - jboss_enterprise_application_platform 7
  - jboss_enterprise_application_platform 8
  - jboss_enterprise_application_platform_expansion_pack
  - jboss_web_server 5
  - single_sign_on 7
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-770
---

## Overview

In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service. 
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Web Server 5, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, … · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-107937.json)
