org.apache.cxf:cxf-rt-rs-security-oauth2
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.cxf:cxf-rt-rs-security-oauth2page 1 of 1
- CVE-2026-50623MEDIUMCVSS 4.8EG 6.5✓ Fixed in 4.1.72026-06-12
vulnerable: 2.6.0 ... 4.1.6 (159 versions)
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed …
- CVE-2026-50627CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.1.72026-06-12
vulnerable: 2.6.0 ... 4.1.6 (159 versions)
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resour…
- CVE-2026-50628CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.1.72026-06-12
vulnerable: 2.6.0 ... 4.1.6 (159 versions)
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security che…
- CVE-2026-50629HIGHCVSS 5.3EG 8.2✓ Fixed in 4.1.72026-06-12
vulnerable: 2.6.0 ... 4.1.6 (159 versions)
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, i…
- CVE-2026-50630MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.1.72026-06-12
vulnerable: 2.6.0 ... 4.1.6 (159 versions)
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characte…
- CVE-2026-50631HIGHCVSS 7.4EG 7.4✓ Fixed in 4.1.72026-06-12
vulnerable: 2.6.0 ... 4.1.6 (159 versions)
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh t…
Check whether org.apache.cxf:cxf-rt-rs-security-oauth2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.cxf:cxf-rt-rs-security-oauth2 CVEs against the assets you own.
Start Free Scan →