ColdFusion CFMail Broken After Security Update: The Felix Cache Fix Explained
If started throwing errors — or pages started hanging and returning HTTP 500 — right after you applied a ColdFusion security update, and the stack trace mentions MailImpl.signMail, VerifyError / "Bad type on operand sta
If started throwing errors — or pages started hanging and returning HTTP 500 — right after you applied a ColdFusion security update, and the stack trace mentions MailImpl.signMail, VerifyError / "Bad type on operand stack," and BouncyCastle (org/bouncycastle/asn1/smime/...), you've hit a known, documented problem. It's not your code. The cause is a stale Apache Felix (OSGi) bundle cache: the update ships new library bundles (including the BouncyCastle crypto libraries ColdFusion uses to sign mail), but ColdFusion's Felix cache still holds the old, now-incompatible bundle versions, so class loading fails when cfmail tries to sign a message. The fix is short: stop ColdFusion, delete the contents of the felix-cache directory, and restart — ColdFusion regenerates the bundle cache from the updated libraries on the next start. The path is /cfusion/bin/felix-cache (or /bin/felix-cache for additional instances). This has been reported on ColdFusion 2021 (Update 21) and ColdFusion 2023 (Update 15), and the same cache-clearing fix applies. This guide explains what the Felix cache is, exactly why the update breaks cfmail, the precise fix steps, how to confirm it worked, and how to stop it happening on the next update.
Read More
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.