We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-41172

Apache CXF: Unrestricted memory consumption in CXF HTTP clients



Assignerapache
Reserved2024-07-17
Published2024-07-19
Updated2024-09-13

Description

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory

Problem types

CWE-401 Missing Release of Memory after Effective Lifetime

Product status

Default status
unaffected

3.6.0, 4.0.0 before 3.6.4, 4.0.5
affected

References

https://lists.apache.org/thread/n2hvbrgwpdtcqdccod8by28ynnolybl6 vendor-advisory

cve.org CVE-2024-41172

nvd.nist.gov CVE-2024-41172

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.