Hostname Verification Issue in Apache CXF Netty Client Transport
CVE-2026-107938

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107938?

The Netty-based HTTP client transport in Apache CXF fails to validate the hostname in the server’s TLS certificate against the host being connected to. This vulnerability allows an attacker who can intercept network traffic to present any trusted certificate, enabling them to impersonate the target service. The flaw exists across both HTTP/1.1 and HTTP/2 protocols, even with the disableCNCheck option set to false. As a consequence, sensitive information such as credentials and messages can be compromised. It is essential for users to upgrade to the fixed versions to mitigate this risk.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.4

Apache CXF 4.0.0 < 4.1.9

Apache CXF 0 < 3.6.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found using Claude agents to study the security of open-source projects
.