← Back to browse · API

CVE-2022-46364

Severity
CRITICAL
CVSS
9.8
EPSS
0.02371
Risk score
40.03
CISA KEV
No
PoC
No
Published
2022-12-13
Modified
2025-04-22
First seen
2026-08-07
Aliases
EUVD-2022-7768, GHSA-X3X3-QWJQ-8GJ4
Products
Apache Software Foundation:Apache CXF 0 <3.4.10, Apache Software Foundation:Apache CXF 0 <3.5.5
Sources
euvd EUVD-2022-7768

Description

A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.

References