CVE-2026-50627
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
脆弱性の種類
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
影響を受ける製品
- apache cxf
参考情報
- https://lists.apache.org/thread/0jfzz9q992957b99tw7hodcqjfyxwb1m
- http://www.openwall.com/lists/oss-security/2026/06/11/4
- https://access.redhat.com/errata/RHSA-2026:37390
- https://access.redhat.com/security/cve/CVE-2026-50627
- https://bugzilla.redhat.com/show_bug.cgi?id=2488298
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50627.json