Apache CXF Token Validation Vulnerability in OIDC Implementation
CVE-2026-65583

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 August 2026

What is CVE-2026-65583?

A vulnerability exists in Apache CXF's OpenID Connect (OIDC) implementation that allows for an authentication bypass via improper validation of self-issued ID tokens. Specifically, the relying-party token validation does not enforce essential claim checks, including issuer, subject, audience, token expiration, and sub_jwk binding. While self-issued ID tokens are not accepted by default, the flaw may still pose a risk if exploited through crafted tokens. Users are strongly advised to upgrade to updated versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this issue.

Affected Version(s)

Apache CXF 4.2.0 < 4.2.3

Apache CXF 4.0.0 < 4.1.8

Apache CXF 0 < 3.6.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guanping Zhang reported this vulnerability.
.