Hostname Verification Issue in Apache CXF Netty Client Transport
CVE-2026-107938
Currently unrated
What is CVE-2026-107938?
The Netty-based HTTP client transport in Apache CXF fails to validate the hostname in the server’s TLS certificate against the host being connected to. This vulnerability allows an attacker who can intercept network traffic to present any trusted certificate, enabling them to impersonate the target service. The flaw exists across both HTTP/1.1 and HTTP/2 protocols, even with the disableCNCheck option set to false. As a consequence, sensitive information such as credentials and messages can be compromised. It is essential for users to upgrade to the fixed versions to mitigate this risk.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.4
Apache CXF 4.0.0 < 4.1.9
Apache CXF 0 < 3.6.13