🔐 CVE Alert

CVE-2026-50634

UNKNOWN 0.0

Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity parsing or signed-header consistency checks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

CWE CWE-347
Vendor apache software foundation
Product apache cxf
Published Jun 12, 2026
Last Updated Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache cxf

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache cxf are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache CXF
4.2.0 < 4.2.2 0 < 4.1.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/9nfwh9d3m4kznxrk1mz98hl0jml18k0p openwall.com: http://www.openwall.com/lists/oss-security/2026/06/11/11

Credits

Mitchell Benjamin / Revamp Studio.