A vulnerability categorized as problematic has been discovered in Apache CXF up to 3.6.11/4.1.7/4.2.2. This affects an unknown function. Executing a manipulation can lead to resource consumption.

This vulnerability appears as CVE-2026-64958. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.