← Vulnerability feed

Vulnerability record · CVE-2010-2076 · published 19 August 2010

CVE-2010-2076: Apache cxf inclusion from untrusted sphere vulnerability

Apache · Cxf

Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.

9.8 CVSS 3.1 Critical EPSS 9.8% · top 4.6% CWE-829 · Inclusion from untrusted sphere
9.8CVSS 3.1 base score, v2 7.5
9.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html Vendor Advisory
http://geronimo.apache.org/21x-security-report.html Release NotesVendor Advisory
http://geronimo.apache.org/22x-security-report.html Release NotesVendor Advisory
http://secunia.com/advisories/40969 Broken LinkVendor Advisory
http://secunia.com/advisories/41016 Broken LinkVendor Advisory
http://secunia.com/advisories/41025 Broken LinkVendor Advisory
http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf ExploitVendor Advisory
http://www.listware.net/201006/cxf-users/60160-important-apache-cxf-security-advisory-cve-2010-2076.html Broken Link
http://www.securityfocus.com/bid/42492 Broken LinkThird Party AdvisoryVDB Entry
https://issues.apache.org/jira/browse/GERONIMO-5383 Third Party Advisory
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.o Mailing ListPatch
http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html Vendor Advisory
http://geronimo.apache.org/21x-security-report.html Release NotesVendor Advisory
http://geronimo.apache.org/22x-security-report.html Release NotesVendor Advisory
http://secunia.com/advisories/40969 Broken LinkVendor Advisory
http://secunia.com/advisories/41016 Broken LinkVendor Advisory
http://secunia.com/advisories/41025 Broken LinkVendor Advisory
http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf ExploitVendor Advisory
http://www.listware.net/201006/cxf-users/60160-important-apache-cxf-security-advisory-cve-2010-2076.html Broken Link
http://www.securityfocus.com/bid/42492 Broken LinkThird Party AdvisoryVDB Entry
https://issues.apache.org/jira/browse/GERONIMO-5383 Third Party Advisory
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.o Mailing ListPatch
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.o Mailing ListPatch

Track CVE-2010-2076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2379Apache cxf vulnerabilityApache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 pol…EPSS 4.1%9.8CVE-2026-68079Apache cxf authentication bypass by capture-replay vulnerabilityIn Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…EPSS 0.68%9.8CVE-2026-66909Apache cxf deserialization of untrusted data vulnerabilityApache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…EPSS 1.1%9.8CVE-2026-49875Apache cxf xml external entity (xxe) vulnerabilityApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…EPSS 0.81%9.8CVE-2026-50628Apache cxf improper input validation vulnerabilityA logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…EPSS 1.0%9.8CVE-2026-44930Apache cxf ldap injection vulnerabilityAn LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…EPSS 0.51%9.8CVE-2025-48913Apache cxf improper input validation vulnerabilityIf untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution cap…EPSS 0.82%9.8CVE-2022-46364Apache cxf server-side request forgery (ssrf) vulnerabilityA SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attack…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2010-2076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.