Authorization Code Injection Vulnerability in Apache CXF by Apache
CVE-2026-57817

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 August 2026

What is CVE-2026-57817?

The Apache CXF is vulnerable to Authorization Code Injection attacks due to insufficient validation of the c_hash parameter within the Hybrid Flow of the OpenID Connect Core 1.0 specification. This vulnerability arises when integrated with a misconfigured or non-compliant Identity Provider (IdP) that does not provide the necessary c_hash parameter. Organizations using affected versions should upgrade to Apache CXF 4.2.3, 4.1.8, or 3.6.12 to mitigate this risk effectively.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.3

Apache CXF 4.0.0 < 4.1.8

Apache CXF 0 < 3.6.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guanping Zhang reported this vulnerability.
.