Apache cxf是美国Apache基金会开源的一个Web服务开发框架。 Apache CXF 4.1.7之前版本和4.2.0至4.2.2之前版本存在加密问题漏洞,该漏洞源于JwsJsonContainerRequestFilter未正确验证签名,可能导致中间人攻击,绕过Content-Type或受保护HTTP标头元数据的签名验证,影响下游JAX-RS实体解析。以下版本受到影响:所有4.1.7之前版本和4.2.0至4.2.2之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0< 4.2.2 |
affected |
4.0.0< 4.1.7 |
affected | ||
< 3.6.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 ~ 4.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50645 | Apache CXF: No restriction on attachment headers per message | |
| CVE-2026-50633 | Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl | |
| CVE-2026-50632 | Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory | |
| CVE-2026-50631 | Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing | |
| CVE-2026-50630 | Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection | |
| CVE-2026-50629 | Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier | |
| CVE-2026-50628 | Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control | |
| CVE-2026-50627 | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator | |
| CVE-2026-49875 | Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointRefer | |
| CVE-2026-50623 | Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService |
No comments yet