Security Advisory

CVE-2026-57817

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-06 10:24:05
Last updated 2026-08-07 03:55:29
Assigner apache
CVSS score not scored
State PUBLISHED

Description

The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.