cbcvebase.

Apache Cxf vulnerabilities

69 known vulnerabilities affecting apache/cxf.

Total CVEs
69
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH24MEDIUM28

Vulnerabilities

Page 1 of 4
CVE-2019-12419P2CRITICALCVSS 9.8≥ 3.2.0, < 3.2.11≥ 3.3.0, < 3.3.42019-11-06
CVE-2019-12419 [CRITICAL] CWE-863 CVE-2019-12419: Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to
nvd
CVE-2012-0803P2CRITICALCVSS 9.8v2.4.5v2.5.12017-08-08
CVE-2012-0803 [CRITICAL] CWE-287 CVE-2012-0803: The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authe The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request.
nvd
CVE-2026-66909P2CRITICALCVSS 9.8fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-66909 [CRITICAL] CWE-502 CVE-2026-66909: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remo
nvd
CVE-2013-2160P3MEDIUMCVSS 5.0PoCv2.5.0v2.5.1+19 more2013-08-19
CVE-2013-2160 [MEDIUM] CWE-399 CVE-2013-2160: The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7 The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.
nvd
CVE-2026-68079P2CRITICALCVSS 9.8fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-68079 [CRITICAL] CWE-294 CVE-2026-68079: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or
nvd
CVE-2026-44930P2CRITICALCVSS 9.8fixed in 3.6.11≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44930 [CRITICAL] CWE-90 CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
nvd
CVE-2026-50628P3CRITICALCVSS 9.8fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50628 [CRITICAL] CWE-20 CVE-2026-50628: A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP addres A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
nvd
CVE-2026-63687P3CRITICALCVSS 9.1fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-63687 [CRITICAL] CWE-345 CVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, a
nvd
CVE-2025-48913P3CRITICALCVSS 9.8fixed in 3.6.8≥ 4.0.0, < 4.0.9+1 more2025-08-08
CVE-2025-48913 [CRITICAL] CWE-20 CVE-2025-48913: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDA If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
nvd
CVE-2024-29736P3CRITICALCVSS 9.1fixed in 3.5.9≥ 3.6.0, < 3.6.4+1 more2024-07-19
CVE-2024-29736 [CRITICAL] CWE-918 CVE-2024-29736: A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3 A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
nvd
CVE-2026-65583P3CRITICALCVSS 9.1fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-65583 [CRITICAL] CWE-345 CVE-2026-65583: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcin Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade t
nvd
CVE-2010-2076P3CRITICALCVSS 9.8≥ 2.0.6, < 2.0.13≥ 2.1, < 2.1.10+1 more2010-08-19
CVE-2010-2076 [CRITICAL] CVE-2010-2076: Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache Servi Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi
nvd
CVE-2022-46364P3CRITICALCVSS 9.8fixed in 3.4.10≥ 3.5.0, < 3.5.52022-12-13
CVE-2022-46364 [CRITICAL] CWE-918 CVE-2022-46364: A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Ap A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
nvd
CVE-2026-49875P3CRITICALCVSS 9.8fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-49875 [CRITICAL] CWE-611 CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.
nvd
CVE-2026-61466P3CRITICALCVSS 9.1fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-61466 [CRITICAL] CWE-304 CVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade t
nvd
CVE-2026-50632P3HIGHCVSS 8.1fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50632 [HIGH] CVE-2026-50632: A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lea A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
nvd
CVE-2026-57818P3HIGHCVSS 8.1fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-57818 [HIGH] CWE-367 CVE-2026-57818: A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
nvd
CVE-2021-40690P3HIGHCVSS 7.5v3.4.42021-09-19
CVE-2021-40690 [HIGH] CWE-200 CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
nvd
CVE-2026-50627P3CRITICALCVSS 9.1fixed in 4.1.7≥ 4.2.0, < 4.2.22026-06-12
CVE-2026-50627 [CRITICAL] CWE-289 CVE-2026-50627: The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4
nvd
CVE-2026-57817P3HIGHCVSS 8.1fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-57817 [HIGH] CWE-20 CVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommend
nvd
Apache Cxf vulnerabilities | cvebase