Apache CXF Runtime JMS Transport
98%
Total Score
99
91
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-859281 cxf-rt-transports-jms is vulnerable to Improper Input Validation in versions 0.0.0 - 4.1.6 and 4.2.0 - 4.2.1. | 0.0.0 - 4.1.64.2.0 - 4.2.1 | High |
CVE-2026-44417 org.apache.cxf:cxf-rt-transports-jms is vulnerable to Improper Input Validation in versions 4.2.0 - 4.2.0, 4.1.0 - 4.1.6 and 0.0.0 - 3.6.11. | 0.0.0 - 3.6.114.1.0 - 4.1.64.2.0 - 4.2.0 | High |
CVE-2025-48913 org.apache.cxf:cxf-rt-transports-jms is vulnerable to Improper Input Validation in versions 0.0.0 - 3.6.8, 4.0.0 - 4.0.9 and 4.1.0 - 4.1.3. | 0.0.0 - 3.6.84.0.0 - 4.0.94.1.0 - 4.1.3 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jakarta.xml.ws:jakarta.xml.ws-api Version * | — | — |
org.apache.cxf:cxf-core Version 4.2.2 | — | — |
org.apache.cxf:cxf-rt-wsdl Version 4.2.2 | — | — |
jakarta.jms:jakarta.jms-api Version * | — | — |
jakarta.transaction:jakarta.transaction-api Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant