CVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the c_hash parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-57817
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-57817 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilitiescert-bund
More from NVD Recent CVEs
- criticalCVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attac…2026-08-07
- criticalCVE-2026-68823: Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacke…2026-08-07
- highCVE-2026-65668: Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to eleva…2026-08-07
- criticalCVE-2026-65667: Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges…2026-08-07
- criticalCVE-2026-63508: Missing authentication for critical function in Microsoft Planetary Computer Pro allows an una…2026-08-07