cbcvebase.

Apache Software Foundation Apache Cxf vulnerabilities

43 known vulnerabilities affecting apache_software_foundation/apache_cxf.

Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH20MEDIUM10

Vulnerabilities

Page 1 of 3
CVE-2026-66909P2CRITICALCVSS 9.8≥ 4.2.0, < 4.2.3≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-66909 [CRITICAL] CWE-502 CVE-2026-66909: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remo
nvd
CVE-2026-68079P2CRITICALCVSS 9.8≥ 4.2.0, < 4.2.3≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-68079 [CRITICAL] CWE-294 CVE-2026-68079: In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or
nvd
CVE-2026-44930P2CRITICALCVSS 9.8≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.1.6+1 more2026-05-22
CVE-2026-44930 [CRITICAL] CWE-90 CVE-2026-44930: An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
cvelistv5nvd
CVE-2026-50628P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.2≥ 4.0.0, < 4.1.7+1 more2026-06-12
CVE-2026-50628 [CRITICAL] CWE-20 CVE-2026-50628: A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP addres A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
nvd
CVE-2026-63687P3CRITICALCVSS 9.1≥ 4.2.0, < 4.2.3≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-63687 [CRITICAL] CWE-345 CVE-2026-63687: Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, a
nvd
CVE-2025-48913P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.1≥ 4.0.0, < 4.1.6+1 more2025-08-08
CVE-2025-48913 [CRITICAL] CWE-20 CVE-2025-48913: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDA If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
nvd
CVE-2024-29736P3CRITICALCVSS 9.1fixed in 3.5.9, 3.6.4, 4.0.52024-07-19
CVE-2024-29736 [CRITICAL] CWE-918 CVE-2024-29736: A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3 A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on REST webservices. The attack only applies if a custom stylesheet parameter is configured.
nvd
CVE-2026-65583P3CRITICALCVSS 9.1≥ 4.2.0, < 4.2.3≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-65583 [CRITICAL] CWE-345 CVE-2026-65583: Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcin Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade t
nvd
CVE-2022-46364P3CRITICALCVSS 9.8fixed in 3.5.5fixed in 3.4.102022-12-13
CVE-2022-46364 [CRITICAL] CWE-918 CVE-2022-46364: A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Ap A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type.
nvd
CVE-2026-49875P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.2≥ 4.0.0, < 4.1.7+1 more2026-06-12
CVE-2026-49875 [CRITICAL] CWE-611 CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.
nvd
CVE-2026-61466P3CRITICALCVSS 9.1fixed in 3.6.12≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-61466 [CRITICAL] CWE-304 CVE-2026-61466: In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade t
nvd
CVE-2026-57818P3HIGHCVSS 8.1≥ 4.2.0, < 4.2.3≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-57818 [HIGH] CWE-367 CVE-2026-57818: A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
nvd
CVE-2026-50627P3CRITICALCVSS 9.1≥ 4.2.0, < 4.2.2≥ 4.0.0, < 4.1.7+1 more2026-06-12
CVE-2026-50627 [CRITICAL] CWE-289 CVE-2026-50627: The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4
nvd
CVE-2026-57817P3HIGHCVSS 8.1≥ 4.2.0, < 4.2.3≥ 4.0.0, < 4.1.8+1 more2026-08-06
CVE-2026-57817 [HIGH] CWE-20 CVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommend
nvd
CVE-2026-44417P3HIGHCVSS 7.5≥ 4.2.0, < 4.2.2≥ 4.0.0, < 4.1.7+1 more2026-05-22
CVE-2026-44417 [HIGH] CWE-20 CVE-2026-44417: The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
cvelistv5nvd
CVE-2018-8039P3HIGHCVSS 8.1vprior to 3.1.16v3.2.x prior to 3.2.52018-07-02
CVE-2018-8039 [HIGH] CWE-755 CVE-2018-8039: It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProp It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the defaul
nvd
CVE-2026-50633P3HIGHCVSS 8.1≥ 4.2.0, < 4.2.2≥ 4.0.0, < 4.1.7+1 more2026-06-12
CVE-2026-50633 [HIGH] CWE-20 CVE-2026-50633: A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
nvd
CVE-2024-28752P3CRITICALCVSS 9.3fixed in 4.0.4, 3.6.3, 3.5.82024-03-15
CVE-2024-28752 [CRITICAL] CWE-918 CVE-2024-28752: A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3 A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
nvd
CVE-2021-30468P3HIGHCVSS 7.5≥ Apache CXF, < 3.4.42021-06-16
CVE-2021-30468 [HIGH] CWE-400 CVE-2021-30468: A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malforme A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
nvd
CVE-2026-50631P3HIGHCVSS 7.4≥ 4.2.0, < 4.2.2≥ 4.0.0, < 4.1.7+1 more2026-06-12
CVE-2026-50631 [HIGH] CWE-367 CVE-2026-50631: A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Toke A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4
nvd