org.apache.cxf:cxf-rt-transports-jms
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.cxf:cxf-rt-transports-jmspage 1 of 1
- CVE-2025-48913CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.1.32025-08-08
vulnerable: 4.1.0, 4.1.1, 4.1.2
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this poss…
- CVE-2026-44417HIGHCVSS 7.5EG 7.5✓ Fixed in 4.2.12026-05-22
vulnerable: 4.2.0
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apa…
Check whether org.apache.cxf:cxf-rt-transports-jms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.cxf:cxf-rt-transports-jms CVEs against the assets you own.
Start Free Scan →