Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97791— Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares validation state between requests

Quick assessment

Affected
Apache Software Foundation Apache CXF
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Apache CXF 中,STSTokenValidator 会在将 SAML 断言发送给安全令牌服务(STS)之前,检查该断言是否由受信任的证书签名。然而,该验证结果被存储在一个所有请求共享的对象中,导致一个请求可能读取到其他请求的验证结果。远程未认证攻击者可以在合法请求处理过程中,发送一个由不受信任证书签名的伪造断言,并且该断言可能在未经过 STS 验证的情况下就被误认为可信。只有那些使用 STSTokenValidator 验证 SAML 令牌且未始终将 alwaysValidateToSts 设置为 t

AI Predicted 7.5 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97791

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares validation state between requests
Source: CVE Program / CVE List V5
Vulnerability Description
In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests, so one request could read another's result. A remote, unauthenticated attacker could send a forged assertion signed with an untrusted certificate while legitimate requests were being processed, and it could be accepted as trusted without ever reaching the STS. Only services that use STSTokenValidator to validate SAML tokens without alwaysValidateToSts set are affected.  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache CXF 4.2.0 ~ 4.2.4 -

II. Public POCs for CVE-2026-97791

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97791

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-97791 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-09 · 13 CVEs total

CVE-2026-103413 8.8 HIGH Apache Camel Karavan: unvalidated Kubernetes resources applied from a project's kubernetes
CVE-2026-103412 8.8 HIGH Apache Camel Karavan: project file name path traversal when committing a project to Git
CVE-2026-108039 Apache CXF: Prevent unbounded XML document size in StaxUtils by adding default element and
CVE-2026-107938 Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.
CVE-2026-107937 Apache CXF: The attachment header size and count limits can be bypassed, which allows deni
CVE-2026-100227 Apache CXF: XML Signature wrapping in JAX-RS XML Security
CVE-2026-97468 Apache CXF: Authentication bypass via weak cache keys for validated STS tokens
CVE-2026-86463 Apache CXF: FIQL Query Parser Denial of Service
CVE-2026-79650 Apache CXF: OIDC RP Open Redirect
CVE-2026-78384 Apache CXF: Unbounded DEFLATE Decompression in CXF JOSE/JWE and SAML Processing (Decompres
CVE-2026-73179 Apache CXF: JPA authorization-code consume is non-atomic
CVE-2026-71575 Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFil

IV. Related Vulnerabilities

V. Comments for CVE-2026-97791

No comments yet


Leave a comment