cbcvebase.
CVE-2026-63687
published 2026-08-06

CVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive…

PriorityP357critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.27%
18.3th percentile
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.123.6.12
apachecxf
apachecxf>= 4.0.0 < 4.1.84.1.8
apachecxf>= 4.2.0 < 4.2.34.2.3
apache_software_foundationapache_cxf< 3.6.123.6.12
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.84.1.8
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.34.2.3

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.