CVE-2026-50629
published 2026-06-12CVE-2026-50629: The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters…
PriorityP333medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.42%
35.2th percentile
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 3.6.12 | 3.6.12 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.cxf/cxf-rt-rs-security-oauth2: apache-cxf: Log injection in OAuth2 server logs
vendor_redhat·2026-06-12·CVSS 5.3
CVE-2026-50629 [MEDIUM] CWE-93 org.apache.cxf/cxf-rt-rs-security-oauth2: apache-cxf: Log injection in OAuth2 server logs
org.apache.cxf/cxf-rt-rs-security-oauth2: apache-cxf: Log injection in OAuth2 server logs
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
A flaw was found in apache-cxf. The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without proper sanitization. A remote attacker could exploit this by injecting arbitrary content, including fake log entries, into the server's log files. This could lead to log manipulation, maki
GHSA
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters.
ghsa_unreviewed·2026-06-12
CVE-2026-50629 [HIGH] CWE-93 The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters.
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
GHSA
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
ghsa·2026-06-12
CVE-2026-50629 [HIGH] CWE-93 Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
Apache CXF OAuth2 Log Injection via Unsanitized Client Identifier
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 OAuth2 neutralization for logs
vuldb·2026-06-11
CVE-2026-50629 [LOW] Apache CXF up to 4.1.6/4.2.1 OAuth2 neutralization for logs
A vulnerability classified as problematic has been found in Apache CXF up to 4.1.6/4.2.1. This impacts an unknown function of the component OAuth2. Performing a manipulation results in improper output neutralization for logs.
This vulnerability is reported as CVE-2026-50629. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published