Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/fzj8yzgfl53gclxrcdrnrx3grcpkq51j | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/08/06/23 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-06 12:16
Updated : 2026-08-07 00:16
NVD link : CVE-2026-65583
Mitre link : CVE-2026-65583
CVE.ORG link : CVE-2026-65583
JSON object : View
Products Affected
apache
- cxf
CWE
CWE-345
Insufficient Verification of Data Authenticity
