Apache CXF JNDI Injection Vulnerability: Early Warning
- Severity
- HIGH
- Affected component
- org.apache.cxf:cxf-rt-transports-jms (maven)
- Affected versions
- >= 4.2.0, <= 4.2.0 or >= cxf-3.6.10, <= cxf-3.6.10 or >= cxf-4.1.5, <= cxf-4.1.5 or >= cxf-4.2.0, <= cxf-4.2.0 or >= cxf-3.6.9, <= cxf-3.6.9 or >= cxf-4.1.4, <= cxf-4.1.4 or >= cxf-3.6.8, <= cxf-3.6.8 or >= cxf-4.1.3, <= cxf-4.1.3 or >= cxf-3.6.7, <= cxf-3.6.7 or >= cxf-4.1.2, <= cxf-4.1.2 or >= cxf-3.6.6, <= cxf-3.6.6 or >= cxf-4.1.1, <= cxf-4.1.1 or >= cxf-4.1.0, <= cxf-4.1.0 or >= cxf-3.6.5, <= cxf-3.6.5 or >= cxf-3.6.4, <= cxf-3.6.4 or >= cxf-3.6.3, <= cxf-3.6.3 or >= cxf-4.0.4, <= cxf-4.0.4 or >= cxf-4.0.3, <= cxf-4.0.3 or >= cxf-3.6.2, <= cxf-3.6.2 or >= cxf-4.0.2, <= cxf-4.0.2 or >= cxf-3.6.1, <= cxf-3.6.1 or >= cxf-4.0.1, <= cxf-4.0.1 or >= cxf-3.6.0, <= cxf-3.6.0 or >= cxf-4.0.0, <= cxf-4.0.0 or >= cxf-3.5.0, <= cxf-3.5.0 or >= cxf-3.4.1, <= cxf-3.4.1 or >= cxf-3.4.0, <= cxf-3.4.0 or >= cxf-3.3.3, <= cxf-3.3.3 or >= cxf-3.3.2, <= cxf-3.3.2 or >= cxf-3.3.1, <= cxf-3.3.1 or >= cxf-3.3.0, <= cxf-3.3.0 or >= cxf-3.2.5, <= cxf-3.2.5 or >= cxf-3.2.4, <= cxf-3.2.4 or >= cxf-3.2.3, <= cxf-3.2.3 or >= cxf-3.2.2, <= cxf-3.2.2 or >= cxf-3.2.1, <= cxf-3.2.1 or >= cxf-3.2.0, <= cxf-3.2.0 or >= cxf-3.1.4, <= cxf-3.1.4 or >= cxf-3.1.3, <= cxf-3.1.3 or >= cxf-3.1.2, <= cxf-3.1.2 or >= cxf-3.1.1, <= cxf-3.1.1 or >= cxf-3.1.0, <= cxf-3.1.0 or >= cxf-3.0.0, <= cxf-3.0.0 or >= cxf-3.0.0-milestone2, <= cxf-3.0.0-milestone2 or >= cxf-2.7.2, <= cxf-2.7.2 or >= cxf-2.7.1, <= cxf-2.7.1 or >= cxf-2.7.0, <= cxf-2.7.0 or >= cxf-2.6.1, <= cxf-2.6.1 or >= cxf-2.6.0, <= cxf-2.6.0 or >= cxf-2.5.1, <= cxf-2.5.1 or >= cxf-2.5.0, <= cxf-2.5.0 or >= cxf-2.4.0, <= cxf-2.4.0 or >= cxf-2.3.0, <= cxf-2.3.0 or >= cxf-2.2.2, <= cxf-2.2.2 or >= cxf-2.2.1, <= cxf-2.2.1 or >= cxf-2.2, <= cxf-2.2 or >= cxf-2.1.2, <= cxf-2.1.2 or >= cxf-2.1, <= cxf-2.1
- Patched version
- 4.2.2, 4.1.7
An early warning has been issued for a JNDI Injection Vulnerability in Apache CXF's JMSConfigFactory. This vulnerability, tracked as CVE-2026-44417 and GHSA-93G8-QQV3-MRX8, could allow code execution if untrusted users configure JMS.
What happened
Apache CXF has reportedly been found to have a JNDI Injection Vulnerability in its JMSConfigFactory component. This vulnerability, identified as CVE-2026-44417 and tracked under GHSA-93G8-QQV3-MRX8, appears to enable code execution capabilities if untrusted users are permitted to configure JMS. An incomplete fix for this vulnerability has been identified. The vulnerability affects a wide range of versions of the org.apache.cxf:cxf-rt-transports-jms component.
The vulnerability was first flagged on June 12, 2026. It is currently under investigation and has not been reported as exploited in the wild. The severity of this vulnerability is high, prompting an urgent review of systems that may be affected.
What to do about it
- Upgrade to versions 4.2.2 or 4.1.7 of org.apache.cxf:cxf-rt-transports-jms to mitigate the vulnerability.
- Review your project dependencies to identify any use of affected versions of org.apache.cxf:cxf-rt-transports-jms.
- If your project uses an affected version, plan and execute an upgrade to a patched version as soon as possible.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
- Consider implementing additional security measures to restrict untrusted user access to JMS configuration until the upgrade is completed.
How 0Day would have caught this
org.apache.cxf:cxf-rt-transports-jms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your project uses any version of org.apache.cxf:cxf-rt-transports-jms from 4.2.0 to 4.2.0 or from cxf-3.6.10 to cxf-3.6.10 or from cxf-4.1.5 to cxf-4.1.5 or from cxf-4.2.0 to cxf-4.2.0 or from cxf-3.6.9 to cxf-3.6.9 or from cxf-4.1.4 to cxf-4.1.4 or from cxf-3.6.8 to cxf-3.6.8 or from cxf-4.1.3 to cxf-4.1.3 or from cxf-3.6.7 to cxf-3.6.7 or from cxf-4.1.2 to cxf-4.1.2 or from cxf-3.6.6 to cxf-3.6.6 or from cxf-4.1.1 to cxf-4.1.1 or from cxf-4.1.0 to cxf-4.1.0 or from cxf-3.6.5 to cxf-3.6.5 or from cxf-3.6.4 to cxf-3.6.4 or from cxf-3.6.3 to cxf-3.6.3 or from cxf-4.0.4 to cxf-4.0.4 or from cxf-4.0.3 to cxf-4.0.3 or from cxf-3.6.2 to cxf-3.6.2 or from cxf-4.0.2 to cxf-4.0.2 or from cxf-3.6.1 to cxf-3.6.1 or from cxf-4.0.1 to cxf-4.0.1 or from cxf-3.6.0 to cxf-3.6.0 or from cxf-4.0.0 to cxf-4.0.0 or from cxf-3.5.0 to cxf-3.5.0 or from cxf-3.4.1 to cxf-3.4.1 or from cxf-3.4.0 to cxf-3.4.0 or from cxf-3.3.3 to cxf-3.3.3 or from cxf-3.3.2 to cxf-3.3.2 or from cxf-3.3.1 to cxf-3.3.1 or from cxf-3.3.0 to cxf-3.3.0 or from cxf-3.2.5 to cxf-3.2.5 or from cxf-3.2.4 to cxf-3.2.4 or from cxf-3.2.3 to cxf-3.2.3 or from cxf-3.2.2 to cxf-3.2.2 or from cxf-3.2.1 to cxf-3.2.1 or from cxf-3.2.0 to cxf-3.2.0 or from cxf-3.1.4 to cxf-3.1.4 or from cxf-3.1.3 to cxf-3.1.3 or from cxf-3.1.2 to cxf-3.1.2 or from cxf-3.1.1 to cxf-3.1.1 or from cxf-3.1.0 to cxf-3.1.0 or from cxf-3.0.0 to cxf-3.0.0 or from cxf-3.0.0-milestone2 to cxf-3.0.0-milestone2 or from cxf-2.7.2 to cxf-2.7.2 or from cxf-2.7.1 to cxf-2.7.1 or from cxf-2.7.0 to cxf-2.7.0 or from cxf-2.6.1 to cxf-2.6.1 or from cxf-2.6.0 to cxf-2.6.0 or from cxf-2.5.1 to cxf-2.5.1 or from cxf-2.5.0 to cxf-2.5.0 or from cxf-2.4.0 to cxf-2.4.0 or from cxf-2.3.0 to cxf-2.3.0 or from cxf-2.2.2 to cxf-2.2.2 or from cxf-2.2.1 to cxf-2.2.1 or from cxf-2.2 to cxf-2.2 or from cxf-2.1.2 to cxf-2.1.2 or from cxf-2.1 to cxf-2.1.
What should I do right now?
Immediately upgrade to versions 4.2.2 or 4.1.7 of org.apache.cxf:cxf-rt-transports-jms to mitigate the vulnerability. Review your project dependencies to identify any use of affected versions and plan an upgrade. Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
Has this vulnerability been patched?
Yes, versions 4.2.2 and 4.1.7 of org.apache.cxf:cxf-rt-transports-jms have been identified as patched versions.
What is the severity of this vulnerability?
The severity of this vulnerability is high.