CVE-2026-50630
published 2026-06-12CVE-2026-50630: A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is…
PriorityP341medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.36%
29.3th percentile
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 3.6.12 | 3.6.12 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.cxf/cxf-rt-rs-security-oauth2: apache-cxf: HTTP header injection and response splitting via CRLF injection
vendor_redhat·2026-06-12·CVSS 6.5
CVE-2026-50630 [MEDIUM] CWE-93 org.apache.cxf/cxf-rt-rs-security-oauth2: apache-cxf: HTTP header injection and response splitting via CRLF injection
org.apache.cxf/cxf-rt-rs-security-oauth2: apache-cxf: HTTP header injection and response splitting via CRLF injection
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
A flaw was found in apache-cxf. This vulnerability, known as a Carriage Return Line Feed (CRLF) injection, allows an attacker to manipulate HTTP response headers. By injecting special characters into the 'realm' parameter
GHSA
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
ghsa·2026-06-12
CVE-2026-50630 [MEDIUM] CWE-113 Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
GHSA
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class.
ghsa_unreviewed·2026-06-12
CVE-2026-50630 [MEDIUM] CWE-113 A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class.
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 OAuth2 response splitting
vuldb·2026-06-11
CVE-2026-50630 [CRITICAL] Apache CXF up to 4.1.6/4.2.1 OAuth2 response splitting
A vulnerability classified as critical was found in Apache CXF up to 4.1.6/4.2.1. Affected is an unknown function of the component OAuth2. Executing a manipulation can lead to http response splitting.
This vulnerability appears as CVE-2026-50630. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published