cbcvebase.
CVE-2026-50629
published 2026-06-12

CVE-2026-50629: The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters…

PriorityP333medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.47%
37.6th percentile
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachecxf< 4.1.74.1.7
apachecxf>= 4.2.0 < 4.2.24.2.2
apache_software_foundationapache_cxf< 4.1.74.1.7
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.24.2.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.