CVE-2026-57817: CWE-20 Improper Input Validation in Apache Software Foundation Apache CXF
CVE-2026-57817 is a high-severity vulnerability in Apache CXF related to improper input validation of the c_hash parameter in OpenID Connect Hybrid Flow. If an Apache CXF relying party (RP) integrates with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash, the RP is vulnerable to authorization code substitution or injection attacks. Fixed versions include 4.2.3, 4.1.8, and 3.6.12.
AI Analysis
Technical Summary
The vulnerability arises because Apache CXF does not properly validate the c_hash parameter as mandated by the OpenID Connect Core 1.0 specification when operating in Hybrid Flow. This improper input validation (CWE-20) allows an attacker to exploit an RP integrated with an IdP that omits the c_hash, enabling authorization code substitution or injection attacks. The issue affects multiple versions of Apache CXF prior to 4.2.3, 4.1.8, and 3.6.12. The CVSS v3.1 base score is 8.1, indicating high severity with network attack vector, high impact on confidentiality, integrity, and availability, and requiring no privileges or user interaction.
Potential Impact
Successful exploitation can lead to full compromise of authorization code integrity, allowing attackers to substitute or inject authorization codes. This can result in unauthorized access to protected resources, potentially compromising confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Users should upgrade Apache CXF to versions 4.2.3, 4.1.8, or 3.6.12 or later, which contain fixes for this vulnerability. Patch status is not explicitly stated as 'official-fix' in the vendor advisory, but the recommended upgrade versions indicate an official fix is available. No other mitigation or temporary workaround is provided.
CVE-2026-57817: CWE-20 Improper Input Validation in Apache Software Foundation Apache CXF
Description
CVE-2026-57817 is a high-severity vulnerability in Apache CXF related to improper input validation of the c_hash parameter in OpenID Connect Hybrid Flow. If an Apache CXF relying party (RP) integrates with a non-compliant or misconfigured Identity Provider (IdP) that omits the c_hash, the RP is vulnerable to authorization code substitution or injection attacks. Fixed versions include 4.2.3, 4.1.8, and 3.6.12.
CVSS v3.1
Score 8.1high
Affected software
Apache Software Foundation
Apache CXF
pkg:maven/Apache Software Foundation/org.apache.cxf:cxf-rt-rs-security-sso-oidcRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because Apache CXF does not properly validate the c_hash parameter as mandated by the OpenID Connect Core 1.0 specification when operating in Hybrid Flow. This improper input validation (CWE-20) allows an attacker to exploit an RP integrated with an IdP that omits the c_hash, enabling authorization code substitution or injection attacks. The issue affects multiple versions of Apache CXF prior to 4.2.3, 4.1.8, and 3.6.12. The CVSS v3.1 base score is 8.1, indicating high severity with network attack vector, high impact on confidentiality, integrity, and availability, and requiring no privileges or user interaction.
Potential Impact
Successful exploitation can lead to full compromise of authorization code integrity, allowing attackers to substitute or inject authorization codes. This can result in unauthorized access to protected resources, potentially compromising confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Users should upgrade Apache CXF to versions 4.2.3, 4.1.8, or 3.6.12 or later, which contain fixes for this vulnerability. Patch status is not explicitly stated as 'official-fix' in the vendor advisory, but the recommended upgrade versions indicate an official fix is available. No other mitigation or temporary workaround is provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-06-25T10:09:34.655Z
- State
- PUBLISHED
Threat ID: 6a746c04bf8831d5399ece9b
Added to database: 08/06/2026, 11:12:04 UTC
Last enriched: 08/13/2026, 16:55:12 UTC
Last updated: 09/19/2026, 22:01:35 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.