CVE-2026-50634: CWE-347 Improper Verification of Cryptographic Signature in Apache Software Foundation Apache CXF
CVE-2026-50634 is a medium severity vulnerability in Apache CXF affecting the JwsJsonContainerRequestFilter component. It allows processing of metadata that was not authenticated by the accepted cryptographic signature, potentially bypassing the application's trust assumptions about signed HTTP headers or content types. This could affect downstream entity parsing or signed-header consistency checks. Fixed versions include Apache CXF 4.2.2, 4.1.7, and 3.6.12.
AI Analysis
Technical Summary
This vulnerability (CWE-347) in Apache CXF's JwsJsonContainerRequestFilter permits an attacker to cause the system to process metadata without proper verification of the cryptographic signature. As a result, the application may incorrectly trust unsigned or tampered metadata such as Content-Type or protected HTTP headers. This undermines the integrity guarantees expected from signature verification and may lead to inconsistent or insecure processing of JAX-RS entities or signed headers. The issue is resolved in Apache CXF versions 4.2.2, 4.1.7, and 3.6.12.
Potential Impact
An attacker can bypass signature verification checks on HTTP metadata, potentially causing the application to accept and process unauthenticated or tampered metadata. This could lead to partial loss of data integrity and trust in signed HTTP headers or content types, affecting downstream processing logic. There is no indication of confidentiality or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Users are advised to upgrade Apache CXF to versions 4.2.2, 4.1.7, or 3.6.12 where this vulnerability is fixed. Patch status is confirmed by the vendor advisory recommending these versions. No other mitigations or temporary fixes are indicated.
CVE-2026-50634: CWE-347 Improper Verification of Cryptographic Signature in Apache Software Foundation Apache CXF
Description
CVE-2026-50634 is a medium severity vulnerability in Apache CXF affecting the JwsJsonContainerRequestFilter component. It allows processing of metadata that was not authenticated by the accepted cryptographic signature, potentially bypassing the application's trust assumptions about signed HTTP headers or content types. This could affect downstream entity parsing or signed-header consistency checks. Fixed versions include Apache CXF 4.2.2, 4.1.7, and 3.6.12.
CVSS v3.1
Score 6.5medium
Affected software
Apache Software Foundation
Apache CXF
pkg:maven/Apache Software Foundation/org.apache.cxf:cxf-rt-rs-security-jose-jaxrsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-347) in Apache CXF's JwsJsonContainerRequestFilter permits an attacker to cause the system to process metadata without proper verification of the cryptographic signature. As a result, the application may incorrectly trust unsigned or tampered metadata such as Content-Type or protected HTTP headers. This undermines the integrity guarantees expected from signature verification and may lead to inconsistent or insecure processing of JAX-RS entities or signed headers. The issue is resolved in Apache CXF versions 4.2.2, 4.1.7, and 3.6.12.
Potential Impact
An attacker can bypass signature verification checks on HTTP metadata, potentially causing the application to accept and process unauthenticated or tampered metadata. This could lead to partial loss of data integrity and trust in signed HTTP headers or content types, affecting downstream processing logic. There is no indication of confidentiality or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Users are advised to upgrade Apache CXF to versions 4.2.2, 4.1.7, or 3.6.12 where this vulnerability is fixed. Patch status is confirmed by the vendor advisory recommending these versions. No other mitigations or temporary fixes are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-06-05T11:26:05.858Z
- State
- PUBLISHED
Threat ID: 6a2bd75fe617e2d83448c005
Added to database: 06/12/2026, 09:54:39 UTC
Last enriched: 08/14/2026, 16:24:19 UTC
Last updated: 09/14/2026, 10:01:31 UTC
Views: 128
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.