cbcvebase.
CVE-2026-57817
published 2026-08-06

CVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is…

PriorityP351high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.44%
36.8th percentile
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.123.6.12
apachecxf
apachecxf>= 4.0.0 < 4.1.84.1.8
apachecxf>= 4.2.0 < 4.2.34.2.3
apache_software_foundationapache_cxf< 3.6.123.6.12
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.84.1.8
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.34.2.3

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.