Cxf

Apache · 69 CVEs

CVE-2026-57818
HIGH

Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

Aug 6, 2026

CVE-2026-61466
CRITICAL

Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation

Aug 6, 2026

CVE-2026-63687
CRITICAL

Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters

Aug 6, 2026

CVE-2026-65583
CRITICAL

Apache CXF: Self-issued ID token claims validation skipped

Aug 6, 2026

CVE-2026-68079
CRITICAL

Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay

Aug 6, 2026

CVE-2026-68481
HIGH

Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

Aug 6, 2026

CVE-2026-65432
HIGH

Apache CXF: XXE via WSDL/XSD import parsing

Aug 6, 2026

CVE-2026-57817
HIGH

Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow

Aug 6, 2026

CVE-2026-66909
CRITICAL

Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage

Aug 6, 2026

CVE-2026-64958
HIGH

Apache CXF: Denial of service via message header attachments

Aug 6, 2026

CVE-2026-57819
HIGH

Apache CXF: No default restriction on the amount of form parameters per message

Aug 6, 2026

CVE-2026-54225
HIGH

Apache CXF: Denial of Service attack via large attachments

Aug 6, 2026

CVE-2026-50645
HIGH

Apache CXF: No restriction on attachment headers per message

Jun 12, 2026

CVE-2026-50634
MEDIUM

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry

Jun 12, 2026

CVE-2026-50633
CRITICAL

Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl

Jun 12, 2026

CVE-2026-50632
CRITICAL

Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory

Jun 12, 2026

CVE-2026-50631
HIGH

Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing

Jun 12, 2026

CVE-2026-50630
MEDIUM

Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection

Jun 12, 2026

CVE-2026-50629
HIGH

Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier

Jun 12, 2026

CVE-2026-50628
CRITICAL

Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control

Jun 12, 2026

CVE-2026-50627
CRITICAL

Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator

Jun 12, 2026

CVE-2026-49875
CRITICAL

Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils

Jun 12, 2026

CVE-2026-50623
MEDIUM

Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService

Jun 12, 2026

CVE-2026-44417
HIGH

Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)

May 22, 2026

CVE-2026-44618
MEDIUM

Apache CXF: XXE vulnerability in WS-Transfer functionality

May 22, 2026

Showing 1 to 25 of 69 CVEs