CVE-2026-50634 Details
Description
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity parsing or signed-header consistency checks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.
A vulnerability exists in Apache CXF's JwsJsonContainerRequestFilter, allowing unvalidated metadata to be processed. This issue arises because the filter can accept metadata that has not been authenticated by the corresponding signature, potentially bypassing application checks that rely on verified signature entries for Content-Type and protected HTTP headers. As a result, this vulnerability could disrupt downstream JAX-RS entity parsing or consistency checks for signed headers. The issue is present in Apache CXF versions 4.2.0 prior to 4.2.2 and versions prior to 4.1.7.
Users are advised to upgrade to Apache CXF versions 4.2.2 or 4.1.7, which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/11/11 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/9nfwh9d3m4kznxrk1mz98hl0jml18k0p | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache cxf | < 4.1.7 >= 4.2.0, < 4.2.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | Initial Analysis | [email protected] |
| Jun 12, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
| Jun 12, 2026 | CVE Modified | CVE |