Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 06 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache cxf |
|
| Vendors & Products |
Apache
Apache cxf |
Thu, 06 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. | |
| Title | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow | |
| Weaknesses | CWE-20 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-06T15:07:59.276Z
Reserved: 2026-06-25T10:09:34.655Z
Link: CVE-2026-57817
Updated: 2026-08-06T15:07:55.351Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T12:45:02Z
-
CWE-20
Improper Input Validation