Authorization Code Injection Vulnerability in Apache CXF by Apache
CVE-2026-57817
Currently unrated
What is CVE-2026-57817?
The Apache CXF is vulnerable to Authorization Code Injection attacks due to insufficient validation of the c_hash parameter within the Hybrid Flow of the OpenID Connect Core 1.0 specification. This vulnerability arises when integrated with a misconfigured or non-compliant Identity Provider (IdP) that does not provide the necessary c_hash parameter. Organizations using affected versions should upgrade to Apache CXF 4.2.3, 4.1.8, or 3.6.12 to mitigate this risk effectively.
Affected Version(s)
Apache CXF 4.2.0 < 4.2.3
Apache CXF 4.0.0 < 4.1.8
Apache CXF 0 < 3.6.12