OpenID Connect Core 1.0 规范要求,在采用 Hybrid(混合)流程时,Relying Party(RP,依赖方)必须验证 参数。如果与不合规或配置错误的身份提供方(IdP)集成的 Apache CXF RP 接收到的授权响应中省略了 参数,则 RP 将易受授权代码替换/注入攻击。建议用户升级至版本 4.2.3、4.1.8 或 3.6.12,这些版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0< 4.2.3 |
affected |
4.0.0< 4.1.8 |
affected | ||
< 3.6.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 ~ 4.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64640 | 5.3 MEDIUM | Apache Polaris: register endpoint reads attacker-controlled storage location before allowe |
| CVE-2026-65583 | Apache CXF: Self-issued ID token claims validation skipped | |
| CVE-2026-54225 | Apache CXF: Denial of Service attack via large attachments | |
| CVE-2026-57819 | Apache CXF: No default restriction on the amount of form parameters per message | |
| CVE-2026-64958 | Apache CXF: Denial of service via message header attachments | |
| CVE-2026-66909 | Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage | |
| CVE-2026-65432 | Apache CXF: XXE via WSDL/XSD import parsing | |
| CVE-2026-68481 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider | |
| CVE-2026-68079 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay | |
| CVE-2025-49506 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | |
| CVE-2026-63687 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters | |
| CVE-2026-61466 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation | |
| CVE-2026-57818 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider | |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | |
| CVE-2026-34191 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle | |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash |
No comments yet