A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/7q08mz8bcbosp25wok7gr537zlp15mfz | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/08/06/20 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-06 12:16
Updated : 2026-08-07 00:16
NVD link : CVE-2026-57818
Mitre link : CVE-2026-57818
CVE.ORG link : CVE-2026-57818
JSON object : View
Products Affected
apache
- cxf
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
