CVE-2026-57817 Details
Description
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
A vulnerability exists in Apache CXF's OpenID Connect implementation, specifically in versions 4.2.0 prior to 4.2.3, 4.0.0 prior to 4.1.8, and 3.6.0 prior to 3.6.12. The issue arises because the framework does not properly validate the 'c_hash' parameter in the Hybrid Flow, as required by the OpenID Connect Core 1.0 specification. This lack of validation can lead to Authorization Code Substitution or Injection attacks, particularly when the Apache CXF Relying Party (RP) is integrated with a non-compliant or misconfigured Identity Provider (IdP) that fails to include the 'c_hash'.
Users are advised to upgrade to Apache CXF versions 4.2.3, 4.1.8, or 3.6.12, all of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/08/06/19 | CVE | |
| https://lists.apache.org/thread/pj63c3pf7kkp1xhr53do704fwj3t3htn | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache cxf | < 3.6.12 >= 4.0.0, < 4.1.8 >= 4.2.0, < 4.2.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | CVE Modified | CVE |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |