🔐 CVE Alert

CVE-2026-107938

UNKNOWN 0.0

Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials.  Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Vendor apache software foundation
Product apache cxf
Published Oct 9, 2026
Last Updated Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache cxf

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache cxf are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache CXF
4.2.0 < 4.2.4 4.0.0 < 4.1.9 0 < 3.6.13

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread.html/ljsjsq1foyjy1v5o22oncw80twx7k2tc openwall.com: http://www.openwall.com/lists/oss-security/2026/10/09/13

Credits

This issue was found using Claude agents to study the security of open-source projects