MAVEN · JUNE 2026 · EARLY WARNING

Apache CXF JNDI Injection Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
org.apache.cxf:cxf-rt-transports-jms (maven)
Affected versions
>= 4.2.0, <= 4.2.0 or >= cxf-3.6.10, <= cxf-3.6.10 or >= cxf-4.1.5, <= cxf-4.1.5 or >= cxf-4.2.0, <= cxf-4.2.0 or >= cxf-3.6.9, <= cxf-3.6.9 or >= cxf-4.1.4, <= cxf-4.1.4 or >= cxf-3.6.8, <= cxf-3.6.8 or >= cxf-4.1.3, <= cxf-4.1.3 or >= cxf-3.6.7, <= cxf-3.6.7 or >= cxf-4.1.2, <= cxf-4.1.2 or >= cxf-3.6.6, <= cxf-3.6.6 or >= cxf-4.1.1, <= cxf-4.1.1 or >= cxf-4.1.0, <= cxf-4.1.0 or >= cxf-3.6.5, <= cxf-3.6.5 or >= cxf-3.6.4, <= cxf-3.6.4 or >= cxf-3.6.3, <= cxf-3.6.3 or >= cxf-4.0.4, <= cxf-4.0.4 or >= cxf-4.0.3, <= cxf-4.0.3 or >= cxf-3.6.2, <= cxf-3.6.2 or >= cxf-4.0.2, <= cxf-4.0.2 or >= cxf-3.6.1, <= cxf-3.6.1 or >= cxf-4.0.1, <= cxf-4.0.1 or >= cxf-3.6.0, <= cxf-3.6.0 or >= cxf-4.0.0, <= cxf-4.0.0 or >= cxf-3.5.0, <= cxf-3.5.0 or >= cxf-3.4.1, <= cxf-3.4.1 or >= cxf-3.4.0, <= cxf-3.4.0 or >= cxf-3.3.3, <= cxf-3.3.3 or >= cxf-3.3.2, <= cxf-3.3.2 or >= cxf-3.3.1, <= cxf-3.3.1 or >= cxf-3.3.0, <= cxf-3.3.0 or >= cxf-3.2.5, <= cxf-3.2.5 or >= cxf-3.2.4, <= cxf-3.2.4 or >= cxf-3.2.3, <= cxf-3.2.3 or >= cxf-3.2.2, <= cxf-3.2.2 or >= cxf-3.2.1, <= cxf-3.2.1 or >= cxf-3.2.0, <= cxf-3.2.0 or >= cxf-3.1.4, <= cxf-3.1.4 or >= cxf-3.1.3, <= cxf-3.1.3 or >= cxf-3.1.2, <= cxf-3.1.2 or >= cxf-3.1.1, <= cxf-3.1.1 or >= cxf-3.1.0, <= cxf-3.1.0 or >= cxf-3.0.0, <= cxf-3.0.0 or >= cxf-3.0.0-milestone2, <= cxf-3.0.0-milestone2 or >= cxf-2.7.2, <= cxf-2.7.2 or >= cxf-2.7.1, <= cxf-2.7.1 or >= cxf-2.7.0, <= cxf-2.7.0 or >= cxf-2.6.1, <= cxf-2.6.1 or >= cxf-2.6.0, <= cxf-2.6.0 or >= cxf-2.5.1, <= cxf-2.5.1 or >= cxf-2.5.0, <= cxf-2.5.0 or >= cxf-2.4.0, <= cxf-2.4.0 or >= cxf-2.3.0, <= cxf-2.3.0 or >= cxf-2.2.2, <= cxf-2.2.2 or >= cxf-2.2.1, <= cxf-2.2.1 or >= cxf-2.2, <= cxf-2.2 or >= cxf-2.1.2, <= cxf-2.1.2 or >= cxf-2.1, <= cxf-2.1
Patched version
4.2.2, 4.1.7
CVE-2026-44417GHSA-93G8-QQV3-MRX8

An early warning has been issued for a JNDI Injection Vulnerability in Apache CXF's JMSConfigFactory. This vulnerability, tracked as CVE-2026-44417 and GHSA-93G8-QQV3-MRX8, could allow code execution if untrusted users configure JMS.

What happened

Apache CXF has reportedly been found to have a JNDI Injection Vulnerability in its JMSConfigFactory component. This vulnerability, identified as CVE-2026-44417 and tracked under GHSA-93G8-QQV3-MRX8, appears to enable code execution capabilities if untrusted users are permitted to configure JMS. An incomplete fix for this vulnerability has been identified. The vulnerability affects a wide range of versions of the org.apache.cxf:cxf-rt-transports-jms component.

The vulnerability was first flagged on June 12, 2026. It is currently under investigation and has not been reported as exploited in the wild. The severity of this vulnerability is high, prompting an urgent review of systems that may be affected.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If org.apache.cxf:cxf-rt-transports-jms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your project uses any version of org.apache.cxf:cxf-rt-transports-jms from 4.2.0 to 4.2.0 or from cxf-3.6.10 to cxf-3.6.10 or from cxf-4.1.5 to cxf-4.1.5 or from cxf-4.2.0 to cxf-4.2.0 or from cxf-3.6.9 to cxf-3.6.9 or from cxf-4.1.4 to cxf-4.1.4 or from cxf-3.6.8 to cxf-3.6.8 or from cxf-4.1.3 to cxf-4.1.3 or from cxf-3.6.7 to cxf-3.6.7 or from cxf-4.1.2 to cxf-4.1.2 or from cxf-3.6.6 to cxf-3.6.6 or from cxf-4.1.1 to cxf-4.1.1 or from cxf-4.1.0 to cxf-4.1.0 or from cxf-3.6.5 to cxf-3.6.5 or from cxf-3.6.4 to cxf-3.6.4 or from cxf-3.6.3 to cxf-3.6.3 or from cxf-4.0.4 to cxf-4.0.4 or from cxf-4.0.3 to cxf-4.0.3 or from cxf-3.6.2 to cxf-3.6.2 or from cxf-4.0.2 to cxf-4.0.2 or from cxf-3.6.1 to cxf-3.6.1 or from cxf-4.0.1 to cxf-4.0.1 or from cxf-3.6.0 to cxf-3.6.0 or from cxf-4.0.0 to cxf-4.0.0 or from cxf-3.5.0 to cxf-3.5.0 or from cxf-3.4.1 to cxf-3.4.1 or from cxf-3.4.0 to cxf-3.4.0 or from cxf-3.3.3 to cxf-3.3.3 or from cxf-3.3.2 to cxf-3.3.2 or from cxf-3.3.1 to cxf-3.3.1 or from cxf-3.3.0 to cxf-3.3.0 or from cxf-3.2.5 to cxf-3.2.5 or from cxf-3.2.4 to cxf-3.2.4 or from cxf-3.2.3 to cxf-3.2.3 or from cxf-3.2.2 to cxf-3.2.2 or from cxf-3.2.1 to cxf-3.2.1 or from cxf-3.2.0 to cxf-3.2.0 or from cxf-3.1.4 to cxf-3.1.4 or from cxf-3.1.3 to cxf-3.1.3 or from cxf-3.1.2 to cxf-3.1.2 or from cxf-3.1.1 to cxf-3.1.1 or from cxf-3.1.0 to cxf-3.1.0 or from cxf-3.0.0 to cxf-3.0.0 or from cxf-3.0.0-milestone2 to cxf-3.0.0-milestone2 or from cxf-2.7.2 to cxf-2.7.2 or from cxf-2.7.1 to cxf-2.7.1 or from cxf-2.7.0 to cxf-2.7.0 or from cxf-2.6.1 to cxf-2.6.1 or from cxf-2.6.0 to cxf-2.6.0 or from cxf-2.5.1 to cxf-2.5.1 or from cxf-2.5.0 to cxf-2.5.0 or from cxf-2.4.0 to cxf-2.4.0 or from cxf-2.3.0 to cxf-2.3.0 or from cxf-2.2.2 to cxf-2.2.2 or from cxf-2.2.1 to cxf-2.2.1 or from cxf-2.2 to cxf-2.2 or from cxf-2.1.2 to cxf-2.1.2 or from cxf-2.1 to cxf-2.1.

What should I do right now?

Immediately upgrade to versions 4.2.2 or 4.1.7 of org.apache.cxf:cxf-rt-transports-jms to mitigate the vulnerability. Review your project dependencies to identify any use of affected versions and plan an upgrade. Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.

Has this vulnerability been patched?

Yes, versions 4.2.2 and 4.1.7 of org.apache.cxf:cxf-rt-transports-jms have been identified as patched versions.

What is the severity of this vulnerability?

The severity of this vulnerability is high.

Sources

Join the 0Day waitlist →

← Back to all threats