CVE-2026-50629
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.
A Log Injection vulnerability (CVE-2026-50629) has been identified in the OAuth2 token service of the org.apache.cxf:cxf-rt-rs-security-oauth2 module, which allows attackers to inject arbitrary content, including forged log entries, into the server's log files by sending a client_id value that contains carriage return, line feed, or other control characters.
Per OWASP: Log injection occurs when an application writes unvalidated user input to its log files, which can allow an attacker to "forge log entries or inject malicious content into the logs."
This issue affects versions 3.1.7 through 3.6.11, 4.0.0 through 4.1.6, and 4.2.0 through 4.2.1 of Apache CXF.
Details
Module Info
- Product: Apache CXF
- Affected packages:
org.apache.cxf:cxf-rt-rs-security-oauth2 - Affected versions: >=3.1.7 <3.6.12, >=4.0.0 <4.1.7, >=4.2.0 <4.2.2
- GitHub repository: https://github.com/apache/cxf
- Published packages: https://central.sonatype.com/artifact/org.apache.cxf/cxf-rt-rs-security-oauth2
- Package manager: Maven
- Fixed in:
- OSS Apache CXF 3.6.12, 4.1.7, 4.2.2
- NES for Apache CXF v3.5.13, v3.4.12
Vulnerability Info
This Medium-severity vulnerability is found in the cxf-rt-rs-security-oauth2 package in versions 3.1.7 through 3.6.11, 4.0.0 through 4.1.6, and 4.2.0 through 4.2.1 of Apache CXF.
Token endpoints built on AbstractTokenService (such as AccessTokenService and TokenRevocationService) resolve the calling client from request data before any client authentication has succeeded. The client identifier comes from the client_id form parameter, or from the user name of an HTTP Basic Authorization header:
protected String retrieveClientId(MultivaluedMap<String, String> params) {
String clientId = params.getFirst(OAuthConstants.CLIENT_ID);
if (clientId == null) {
clientId = (String)getMessageContext().get(OAuthConstants.CLIENT_ID);
}
if (clientId == null && clientIdProvider != null) {
clientId = clientIdProvider.getClientId(getMessageContext());
}
return clientId;
}
That value is passed to getClient. When no registered client matches it, as is the case for an arbitrary attacker-chosen value, the raw identifier is concatenated into a warning log message:
protected Client getClient(String clientId, String clientSecret, MultivaluedMap<String, String> params) {
if (clientId == null) {
reportInvalidRequestError("Client ID is null");
return null;
}
Client client = null;
try {
client = getValidClient(clientId, clientSecret, params);
} catch (OAuthServiceException ex) {
LOG.warning("No valid client found for clientId: " + clientId);
if (ex.getError() != null) {
reportInvalidClient(ex.getError());
return null;
}
}
if (client == null) {
LOG.warning("No valid client found for clientId: " + clientId);
reportInvalidClient();
}
return client;
}
No control characters are removed or escaped before the value reaches the logger. An unauthenticated attacker can therefore send a token request such as client_id=unknown%0d%0a<forged log line> with any client_secret, and the CR/LF sequence starts a new line in line-oriented log files. The injected text can impersonate legitimate log records (for example successful token grants or other users' activity), hide or confuse evidence of an attack during incident response, and feed misleading data to log monitoring and SIEM tooling that parses these files.
Mitigation
Only recent versions of Apache CXF are community-supported. The affected 3.4.x and 3.5.x lines are End-of-Life and will not receive public updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Guanping Zhang (finder)