{"api_version":"v1","generated_at":"2026-10-06T18:40:00+00:00","product":{"cve_count":45,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-cxf-3fc8948c5492","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache CXF","next_cursor":null,"observations":[{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-57818","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57818","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T00:01:42.058Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-57818","primary_source":"","published":"2026-08-06T11:24:53.590Z"},{"affected":"< 3.6.12; 4.0.0 < 4.1.8; 4.2.0 < 4.2.3","affected_versions_present":true,"cve_id":"CVE-2026-61466","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61466","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T00:01:45.092Z","patch_url":"","primary_source":"","published":"2026-08-06T11:24:27.466Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-63687","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63687","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T00:01:46.574Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-63687","primary_source":"","published":"2026-08-06T11:23:45.175Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-65583","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65583","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T00:01:49.572Z","patch_url":"","primary_source":"","published":"2026-08-06T11:23:17.421Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-68079","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68079","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T00:01:53.998Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-68079","primary_source":"","published":"2026-08-06T11:22:57.938Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-68481","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68481","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T00:01:55.439Z","patch_url":"","primary_source":"","published":"2026-08-06T11:22:37.929Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-65432","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65432","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T00:01:48.075Z","patch_url":"","primary_source":"","published":"2026-08-06T10:26:12.142Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-57817","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57817","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T03:55:29.695Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-57817","primary_source":"","published":"2026-08-06T10:24:05.877Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-66909","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-66909","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T00:01:52.513Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-66909","primary_source":"","published":"2026-08-06T10:23:23.571Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-64958","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-64958","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-06T15:10:53.292Z","patch_url":"","primary_source":"","published":"2026-08-06T10:13:04.069Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-57819","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57819","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T00:01:43.594Z","patch_url":"","primary_source":"","published":"2026-08-06T10:12:26.243Z"},{"affected":"4.2.0 < 4.2.3; 4.0.0 < 4.1.8; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-54225","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54225","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T00:01:38.618Z","patch_url":"","primary_source":"","published":"2026-08-06T10:11:41.498Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50645","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50645","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:43:56.015Z","patch_url":"","primary_source":"","published":"2026-06-12T09:06:54.819Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50634","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50634","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:43:39.789Z","patch_url":"","primary_source":"","published":"2026-06-12T09:05:53.768Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50633","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:43:35.206Z","patch_url":"","primary_source":"","published":"2026-06-12T09:02:02.547Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50632","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50632","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T12:43:28.785Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-50632","primary_source":"","published":"2026-06-12T09:00:48.530Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50631","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50631","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:43:22.536Z","patch_url":"","primary_source":"","published":"2026-06-12T08:59:40.200Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50630","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50630","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:43:16.673Z","patch_url":"","primary_source":"","published":"2026-06-12T08:58:27.181Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50629","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50629","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:43:09.466Z","patch_url":"","primary_source":"","published":"2026-06-12T08:57:22.534Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50628","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50628","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-10T12:05:47.240Z","patch_url":"","primary_source":"","published":"2026-06-12T08:56:28.526Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50627","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50627","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-10T12:05:49.743Z","patch_url":"","primary_source":"","published":"2026-06-12T08:55:41.657Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-49875","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49875","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T12:42:46.763Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-49875","primary_source":"","published":"2026-06-12T08:54:50.103Z"},{"affected":"4.2.0 < 4.2.2; 4.0.0 < 4.1.7; < 3.6.12","affected_versions_present":true,"cve_id":"CVE-2026-50623","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50623","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T12:42:50.769Z","patch_url":"","primary_source":"","published":"2026-06-12T08:52:05.767Z"},{"affected":"4.2.0 < 4.2.1; 4.0.0 < 4.1.6; < 3.6.11","affected_versions_present":true,"cve_id":"CVE-2026-44417","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44417","fixed":"Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-07-15T00:54:13.279Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-44417","primary_source":"","published":"2026-05-22T12:17:25.102Z"},{"affected":"4.2.0 < 4.2.1; 4.0.0 < 4.1.6; < 3.6.11","affected_versions_present":true,"cve_id":"CVE-2026-44618","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44618","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-22T21:26:21.841Z","patch_url":"","primary_source":"","published":"2026-05-22T12:17:14.591Z"},{"affected":"4.2.0 < 4.2.1; 4.0.0 < 4.1.6; < 3.6.11","affected_versions_present":true,"cve_id":"CVE-2026-44930","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44930","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-20T12:04:41.035Z","patch_url":"","primary_source":"","published":"2026-05-22T12:16:47.230Z"},{"affected":"4.1.0 < 4.1.3; 4.0.0 < 4.0.9; < 3.6.8","affected_versions_present":true,"cve_id":"CVE-2025-48913","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48913","fixed":"Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-02-26T17:49:47.500Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-48913","primary_source":"","published":"2025-08-08T09:21:22.208Z"},{"affected":"3.5.10 < 3.5.11; 3.6.5 < 3.6.6; 4.0.6 < 4.0.7; 4.1.0 < 4.1.1","affected_versions_present":true,"cve_id":"CVE-2025-48795","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48795","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-04T21:11:06.901Z","patch_url":"","primary_source":"","published":"2025-07-15T14:26:44.758Z"},{"affected":"< 3.5.10; 3.6.0 < 3.6.5; 4.0.0 < 4.0.6","affected_versions_present":true,"cve_id":"CVE-2025-23184","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-23184","fixed":"Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-12-15T15:58:16.867Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-23184","primary_source":"","published":"2025-01-21T09:35:37.468Z"},{"affected":"3.6.0, 4.0.0 < 3.6.4, 4.0.5","affected_versions_present":true,"cve_id":"CVE-2024-41172","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41172","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-13T17:05:12.209Z","patch_url":"","primary_source":"","published":"2024-07-19T08:50:43.766Z"},{"affected":"< 4.0.5, 3.6.4, 3.5.9","affected_versions_present":true,"cve_id":"CVE-2024-32007","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32007","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-13T17:04:44.644Z","patch_url":"","primary_source":"","published":"2024-07-19T08:50:31.832Z"},{"affected":"< 3.5.9, 3.6.4, 4.0.5","affected_versions_present":true,"cve_id":"CVE-2024-29736","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29736","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-11-15T13:08:15.763Z","patch_url":"","primary_source":"","published":"2024-07-19T08:50:08.265Z"},{"affected":"< 4.0.4, 3.6.3, 3.5.8","affected_versions_present":true,"cve_id":"CVE-2024-28752","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28752","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:47:30.605Z","patch_url":"","primary_source":"","published":"2024-03-15T10:27:30.083Z"},{"affected":"< 3.5.5; < 3.4.10","affected_versions_present":true,"cve_id":"CVE-2022-46364","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-46364","fixed":"Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-04-22T02:48:36.211Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-46364","primary_source":"","published":"2022-12-13T16:20:26.765Z"},{"affected":"3.5 < 3.5.5; 3.4 < 3.4.10","affected_versions_present":true,"cve_id":"CVE-2022-46363","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-46363","fixed":"Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-04-22T02:50:45.431Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-46363","primary_source":"","published":"2022-12-13T14:46:55.619Z"},{"affected":"Apache CXF < 3.4.4","affected_versions_present":true,"cve_id":"CVE-2021-30468","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-30468","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T22:32:41.089Z","patch_url":"https://www.oracle.com/security-alerts/cpuoct2021.html","primary_source":"","published":"2021-06-16T12:00:18.000Z"},{"affected":"unspecified < 3.4.3; unspecified < 3.3.10","affected_versions_present":true,"cve_id":"CVE-2021-22696","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-22696","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:27:45.767Z","patch_url":"https://www.oracle.com/security-alerts/cpuoct2021.html","primary_source":"","published":"2021-04-02T10:05:14.000Z"},{"affected":"unspecified < 3.4.1; unspecified < 3.3.8","affected_versions_present":true,"cve_id":"CVE-2020-13954","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-13954","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:27:30.592Z","patch_url":"https://www.oracle.com/security-alerts/cpujan2021.html","primary_source":"","published":"2020-11-12T12:45:14.000Z"},{"affected":"prior to 3.1.16; 3.2.x prior to 3.2.5","affected_versions_present":true,"cve_id":"CVE-2018-8039","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-8039","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T04:04:46.184Z","patch_url":"https://github.com/apache/cxf/commit/fae6fabf9bd7647f5e9cb68897a7d72b545b741b","primary_source":"","published":"2018-07-02T13:00:00.000Z"},{"affected":"prior to 3.1.14; 3.2.x prior to 3.2.1","affected_versions_present":true,"cve_id":"CVE-2017-12624","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12624","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T00:05:34.380Z","patch_url":"","primary_source":"","published":"2017-11-14T16:00:00.000Z"},{"affected":"prior to 3.0.13; 3.1.x prior to 3.1.10","affected_versions_present":true,"cve_id":"CVE-2017-3156","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-3156","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T23:16:01.996Z","patch_url":"","primary_source":"","published":"2017-08-10T18:00:00.000Z"},{"affected":"prior to 3.0.12; 3.1.x prior to 3.1.9","affected_versions_present":true,"cve_id":"CVE-2016-8739","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-8739","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T22:51:45.164Z","patch_url":"http://cxf.apache.org/security-advisories.data/CVE-2016-8739.txt.asc","primary_source":"","published":"2017-08-10T18:00:00.000Z"},{"affected":"prior to 3.0.12; 3.1.x prior to 3.1.9","affected_versions_present":true,"cve_id":"CVE-2016-6812","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-6812","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T00:51:19.414Z","patch_url":"http://cxf.apache.org/security-advisories.data/CVE-2016-6812.txt.asc","primary_source":"","published":"2017-08-10T16:00:00.000Z"},{"affected":"3.1.x before 3.1.11; versions before 3.0.13","affected_versions_present":true,"cve_id":"CVE-2017-5656","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5656","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T15:11:48.432Z","patch_url":"http://cxf.apache.org/security-advisories.data/CVE-2017-5656.txt.asc?version=1&modificationDate=1492515113282&api=v2","primary_source":"","published":"2017-04-18T16:00:00.000Z"},{"affected":"prior to 3.0.13; 3.1.x prior to 3.1.11","affected_versions_present":true,"cve_id":"CVE-2017-5653","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5653","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T15:11:48.424Z","patch_url":"http://cxf.apache.org/security-advisories.data/CVE-2017-5653.txt.asc?version=1&modificationDate=1492515074710&api=v2","primary_source":"","published":"2017-04-18T16:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
