The ColdFusion team has released a

security hotfix for ColdFusion 10.x and 11.x

to provent a possible DoS attack (this one does not affect CF9).