Apache CXF 的 OpenID Connect (OIDC) 依赖方令牌验证功能在默认情况下未强制执行必要的声明检查(如签发者/主体/受众/时间以及 sub_jwk 绑定),从而可能接受自签发的 ID 令牌,导致攻击者通过构造恶意令牌实现身份认证绕过。但请注意,Apache CXF 的验证器默认并不接受自签发的 ID 令牌。建议用户升级至修复该问题的版本,包括 4.2.3、4.1.8 或 3.6.12 版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0< 4.2.3 |
affected |
4.0.0< 4.1.8 |
affected | ||
< 3.6.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 ~ 4.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64640 | 5.3 MEDIUM | Apache Polaris: register endpoint reads attacker-controlled storage location before allowe |
| CVE-2026-68079 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay | |
| CVE-2025-49506 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack | |
| CVE-2026-32327 | Apache Portable Runtime Utility: apr-util XML stack recursion crash | |
| CVE-2026-34191 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle | |
| CVE-2026-34501 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client | |
| CVE-2026-34502 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client | |
| CVE-2026-57818 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider | |
| CVE-2026-61466 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation | |
| CVE-2026-63687 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters | |
| CVE-2026-68481 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider | |
| CVE-2026-65432 | Apache CXF: XXE via WSDL/XSD import parsing | |
| CVE-2026-57817 | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow | |
| CVE-2026-66909 | Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage | |
| CVE-2026-64958 | Apache CXF: Denial of service via message header attachments | |
| CVE-2026-57819 | Apache CXF: No default restriction on the amount of form parameters per message | |
| CVE-2026-54225 | Apache CXF: Denial of Service attack via large attachments |
No comments yet