CVE-2026-57817
published 2026-08-06CVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is…
PriorityP351high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.44%
36.8th percentile
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 3.6.12 | 3.6.12 |
| apache | cxf | — | — |
| apache | cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache | cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
| apache_software_foundation | apache_cxf | < 3.6.12 | 3.6.12 |
| apache_software_foundation | apache_cxf | >= 4.0.0 < 4.1.8 | 4.1.8 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.3 | 4.2.3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.cxf/cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation
vendor_redhat·2026-08-06·CVSS 8.1
CVE-2026-57817 [HIGH] CWE-303 org.apache.cxf/cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation
org.apache.cxf/cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
A flaw was found in Apache CXF. When operating in the OpenID Connect Hybrid Flow, Apache CXF does not enforce the validation of the `c_hash` parameter. This vulnerability allows a remote attacker, through a non-compliant or misconfigured Identity Provider (IdP), to perform A
GHSA
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow.
ghsa_unreviewed·2026-08-06
CVE-2026-57817 [CRITICAL] CWE-20 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow.
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
No detection rules found.
No public exploits indexed.
2026-08-06
Published