Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107938— Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.

Quick assessment

Affected
Apache Software Foundation Apache CXF
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Apache CXF 中,基于 Netty 的 HTTP 客户端传输组件(cxf-rt-transports-http-netty-client)未验证服务器 TLS 证书中的主机名是否与正在调用的目标主机相匹配。该问题在 HTTP/1.1 和 HTTP/2 协议下均存在,即使将 disableCNCheck 参数保持在其默认值 false 也不例外。虽然证书链会按照配置的信任库进行验证,但服务端的身份并未得到验证。攻击者若能拦截网络流量,即可出示客户端信任的任何证书(例如,由公共证书颁发机构签发的、属于攻击者

AI Predicted 8.1 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107938

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.
Source: CVE Program / CVE List V5
Vulnerability Description
In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials.  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache CXF 4.2.0 ~ 4.2.4 -

II. Public POCs for CVE-2026-107938

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107938

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-107938 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-09 · 13 CVEs total

CVE-2026-103413 8.8 HIGH Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes
CVE-2026-103412 8.8 HIGH Apache Camel Karavan: project file name path traversal when committing a project to Git
CVE-2026-108039 Apache CXF: Prevent unbounded XML document size in StaxUtils by adding default element and
CVE-2026-107937 Apache CXF: The attachment header size and count limits can be bypassed, which allows deni
CVE-2026-100227 Apache CXF: XML Signature wrapping in JAX-RS XML Security
CVE-2026-97791 Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares valid
CVE-2026-97468 Apache CXF: Authentication bypass via weak cache keys for validated STS tokens
CVE-2026-86463 Apache CXF: FIQL Query Parser Denial of Service
CVE-2026-79650 Apache CXF: OIDC RP Open Redirect
CVE-2026-78384 Apache CXF: Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing (Decompres
CVE-2026-73179 Apache CXF: JPA authorization-code consume is non-atomic
CVE-2026-71575 Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFil

IV. Related Vulnerabilities

V. Comments for CVE-2026-107938

No comments yet


Leave a comment