CVE-2022-46364 is a server-side request forgery vulnerability in Apache CXF versions earlier than 3.4.10 and 3.5.5. When processing an MTOM request, CXF parses the href attribute of an XOP:Include element without adequately restricting the referenced resource. A crafted href can cause the CXF-hosting server to initiate requests to attacker-selected resources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains a README and one Python 3 entry point, exploit.py. The script uses requests to POST a multipart/related application/xop+xml SOAP message to a user-supplied Apache CXF endpoint. Its xop:Include href is attacker controlled, targeting CVE-2022-46364's unsafe URI handling to request arbitrary HTTP resources from the CXF server or attempt file:// local-file reads. Modes are available for arbitrary SSRF URLs, local paths, and a single host:port HTTP probe; responses with HTTP 200 are printed verbatim. This is a standalone, basic operational PoC rather than a framework module. Reliability is limited because the body assumes a specific devarea.htb submitReport SOAP contract and appears to contain an invalid closing XML tag with an embedded zero-width character, so adaptation/correction is likely needed for successful exploitation.
This repository is a small standalone Python proof-of-concept exploit for CVE-2022-46364 affecting Apache CXF MTOM/XOP processing. The repo contains one executable code file (CVE-2022-46364.py), a README with usage/adaptation guidance, and an editor settings file. The Python script uses requests, argparse, regex, and base64 to craft a multipart/related SOAP request with Content-Type application/xop+xml and injects an xop:Include element whose href is a file:// URI. When sent to a vulnerable Apache CXF SOAP endpoint, the server dereferences the supplied URI during attachment resolution, reads the local file, and returns its contents in the SOAP response. The script then extracts base64 data from the <return> element and decodes it for the operator. The exploit is hardcoded for the Hack The Box DevArea employeeservice endpoint and SOAP structure, but the README explains how to adapt the namespace, operation name, and parameter layout to other vulnerable WSDLs. Although the vulnerability can also enable SSRF to HTTP/HTTPS resources, the implemented exploit capability in code is specifically arbitrary file read, not generalized SSRF automation or code execution.
Small two-file repository containing a Python exploit script and README documentation for CVE-2022-46364 against Apache CXF in the Hack The Box DevArea environment. The main file, exploit.py, is a standalone CLI tool that accepts a target SOAP endpoint (-u/--url) and a resource (-r/--resource). It builds a multipart/related SOAP request with MTOM/XOP content, embedding an <xop:Include> href that points either to a local file via file:/// or to an HTTP URL for SSRF. The script sends the request with requests.post(), searches the SOAP response for a <return>...</return> element, strips leading non-Base64 characters, decodes the content, and prints the recovered plaintext. The exploit’s core capability is arbitrary file read and internal resource retrieval through server-side attachment fetching, not code execution. Repository structure is minimal and purpose-built: README.md explains the vulnerability, prerequisites, and usage examples; exploit.py implements the full exploit workflow including payload construction, request dispatch, and response decoding.
This repository is a small standalone Python exploit for CVE-2022-46364 affecting Apache CXF. It contains only two files: a README with usage/examples and a single executable script, exploit.py, which is the main entry point. The script is not part of a larger exploitation framework. Core purpose: exploit Apache CXF's unsafe handling of XOP:Include href values inside MTOM SOAP requests. Instead of restricting href to local multipart attachments, vulnerable CXF versions dereference arbitrary URIs. The exploit weaponizes this by taking a normal captured SOAP request, parsing its XML body, replacing a chosen leaf element with an injected <xop:Include href="..."/>, wrapping the message as multipart/related MTOM, and sending it back to the target endpoint. Main capabilities observed in the code and README: - Parse a raw HTTP request file into method, path, host, headers, and SOAP body. - Rebuild the request as MTOM/XOP with attacker-controlled href values. - Auto-detect injectable XML fields by testing leaf elements with file:///etc/passwd. - Read a single arbitrary local file from the target via file:// URIs. - Fuzz multiple file paths from a supplied wordlist to enumerate readable files. - Perform SSRF by supplying http:// URLs, including localhost/internal services and metadata endpoints. - Decode and print returned content, and save findings to output. Repository structure is simple and purpose-built: - README.md: documents vulnerability background, prerequisites, CLI usage, modes, examples, and sample targets/wordlists. - exploit.py: implements request parsing, XML manipulation, MTOM payload generation, HTTP sending, field discovery, file fuzzing, and CLI orchestration. The exploit is operational rather than a mere detector because it actively performs exploitation and retrieves content. However, it uses a straightforward hardcoded technique rather than a modular payload framework, so OPERATIONAL is the best fit.
Small PoC repository for CVE-2022-46364 containing one executable Bash exploit script (cfx_lfi.sh), a README, license, and .gitignore. The script is a remote unauthenticated-or-low-friction file-read exploit against an Apache CXF SOAP service vulnerable to XOP Include local file inclusion. It builds a multipart/related POST request with Content-Type application/xop+xml and embeds an attacker-controlled <xop:Include href="$FILE"/> inside a SOAP body element (<employeeName>). The target endpoint is hardcoded as http://Target_IP:8080/employeeservice and must be manually edited. The script sends the request with curl, then parses the SOAP response using sed to extract data between <employeeName> tags. If content is found, it prints the target and requested file and attempts base64 decoding, otherwise it dumps the raw response. Repository purpose is straightforward exploitation and demonstration of arbitrary file read, not persistence, code execution, or post-exploitation. No framework usage, no modularization, and no advanced evasion or automation are present.
This repository is a small standalone proof-of-concept for CVE-2022-46364 affecting Apache CXF MTOM/XOP processing. It contains two files: a README with vulnerability background, usage examples, and mitigation guidance, and a single Python exploit script (exploit.py) that serves as the operational entry point. The exploit script uses Python requests to POST a crafted multipart/related SOAP message to a target CXF endpoint. The SOAP body embeds an xop:Include element with an attacker-controlled href. Because vulnerable CXF versions dereference the URI, the script can coerce the server into fetching arbitrary HTTP URLs (SSRF), opening local files via file:// (LFI), and making simple requests to internal host:port combinations for reconnaissance. The script exposes these capabilities through CLI options: --url for arbitrary SSRF, --file for local file read, and --scan for internal service probing. If no mode is supplied, it defaults to attempting file:///etc/passwd. Notable implementation details: the target URL is built from a base URL plus endpoint path using urljoin; the request Content-Type is set to multipart/related with application/xop+xml; and the payload is a hardcoded SOAP request referencing a sample namespace and operation (dev:submitReport). The code prints the full HTTP response body when status 200 is returned, implying the operator is expected to manually inspect returned SOAP content for exfiltrated data. Overall, this is a real exploit PoC rather than a detector. It is not part of a larger framework, has limited automation, and uses a basic hardcoded SOAP structure, making it best classified as OPERATIONAL rather than weaponized.
This repository is a small standalone Python exploit for CVE-2022-46364, an SSRF vulnerability in Apache CXF affecting versions earlier than 3.5.5 and 3.4.10. The repo contains three files: a single executable exploit script (CVE-2022-46364.py), a README with usage and attack flow, and .gitattributes. The exploit is not part of a larger framework. The main script defines a CXFExploit class that builds one of two SOAP payload variants: an MTOM multipart/related request or a plain SOAP text/xml request. In both cases, the payload embeds an xop:Include element whose href attribute is fully attacker-controlled via the --ssrf-url argument. This is the core exploit primitive: when the vulnerable CXF service parses the SOAP body, it dereferences the supplied href and fetches the referenced resource server-side. Operational flow: the user supplies a vulnerable SOAP endpoint URL (--target), an SSRF target resource (--ssrf-url), and an optional domain used in the SOAP namespace (--domain). The script sends an HTTP POST with SOAPAction set to an empty string and a browser-like User-Agent. After receiving the response, it prints a snippet for debugging and then attempts to extract Base64-encoded data from several possible response patterns: free text following 'Report received from', a <return> element, or an <employeeName> element. If decoding succeeds, the script prints the exfiltrated content. Exploit capabilities are focused on data exfiltration through SSRF rather than code execution. The examples and README indicate intended targets such as local files (file:///etc/passwd), localhost services (127.0.0.1), and cloud metadata endpoints (169.254.169.254). This makes the exploit useful for reading sensitive files, enumerating internal services, and retrieving cloud instance metadata or credentials if the target environment permits access. The code is functional and offensive rather than merely demonstrative: it automates payload generation, request delivery, response parsing, and Base64 decoding. However, it does not include advanced payload staging, chaining, or framework integration, so OPERATIONAL is the best maturity fit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SSRF vulnerability in Apache CXF SOAP MTOM processing caused by improper validation of the URI scheme in the xop:Include href attribute.
Server-side request forgery vulnerability in Apache CXF.
Server-side request forgery vulnerability in Apache CXF.
Server-side request forgery vulnerability in Apache CXF.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.