CVE-2026-57818

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-06 12:16

Updated : 2026-08-07 00:16


NVD link : CVE-2026-57818

Mitre link : CVE-2026-57818

CVE.ORG link : CVE-2026-57818


JSON object : View

Products Affected

apache

  • cxf
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition