CVE-2026-57818
- EPSS 0.34%
- Veröffentlicht 06.08.2026 11:24:53
- Zuletzt bearbeitet 07.08.2026 00:16:32
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versi...
CVE-2026-61466
- EPSS 0.44%
- Veröffentlicht 06.08.2026 11:24:27
- Zuletzt bearbeitet 07.08.2026 00:16:34
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to...
CVE-2026-63687
- EPSS 0.27%
- Veröffentlicht 06.08.2026 11:23:45
- Zuletzt bearbeitet 07.08.2026 00:16:37
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret ...
CVE-2026-65583
- EPSS 0.26%
- Veröffentlicht 06.08.2026 11:23:17
- Zuletzt bearbeitet 07.08.2026 00:16:38
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that sel...
CVE-2026-68079
- EPSS 0.41%
- Veröffentlicht 06.08.2026 11:22:57
- Zuletzt bearbeitet 07.08.2026 00:16:39
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The author...
CVE-2026-68481
- EPSS 0.43%
- Veröffentlicht 06.08.2026 11:22:37
- Zuletzt bearbeitet 07.08.2026 00:16:40
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization se...
CVE-2026-65432
- EPSS 0.41%
- Veröffentlicht 06.08.2026 10:26:12
- Zuletzt bearbeitet 07.08.2026 00:16:37
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTY...
CVE-2026-57817
- EPSS 0.44%
- Veröffentlicht 06.08.2026 10:24:05
- Zuletzt bearbeitet 07.08.2026 05:17:02
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_h...
CVE-2026-66909
- EPSS 0.69%
- Veröffentlicht 06.08.2026 10:23:23
- Zuletzt bearbeitet 07.08.2026 00:16:39
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious seri...
CVE-2026-64958
- EPSS 0.41%
- Veröffentlicht 06.08.2026 10:13:04
- Zuletzt bearbeitet 06.08.2026 18:40:24
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which f...