Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache cxf |
|
| Vendors & Products |
Apache
Apache cxf |
Fri, 09 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-363 |
Fri, 09 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 09 Oct 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests, so one request could read another's result. A remote, unauthenticated attacker could send a forged assertion signed with an untrusted certificate while legitimate requests were being processed, and it could be accepted as trusted without ever reaching the STS. Only services that use STSTokenValidator to validate SAML tokens without alwaysValidateToSts set are affected. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue. | |
| Title | Apache CXF: STSTokenValidator can accept untrusted SAML assertions because it shares validation state between requests | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-09T11:08:04.093Z
Reserved: 2026-09-25T04:38:00.142Z
Link: CVE-2026-97791
No data.
Status : Received
Published: 2026-10-09T11:17:03.380
Modified: 2026-10-09T12:17:13.370
Link: CVE-2026-97791
No data.
OpenCVE Enrichment
Updated: 2026-10-09T13:00:07Z
-
CWE-363
Race Condition Enabling Link Following