CVE-2026-50629

Log Injection
Affects
Apache CXF
in
Apache CXF
No items found.
Versions
>=3.1.7 <3.6.12, >=4.0.0 <4.1.7, >=4.2.0 <4.2.2

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

A Log Injection vulnerability (CVE-2026-50629) has been identified in the OAuth2 token service of the org.apache.cxf:cxf-rt-rs-security-oauth2 module, which allows attackers to inject arbitrary content, including forged log entries, into the server's log files by sending a client_id value that contains carriage return, line feed, or other control characters.

Per OWASP: Log injection occurs when an application writes unvalidated user input to its log files, which can allow an attacker to "forge log entries or inject malicious content into the logs."

This issue affects versions 3.1.7 through 3.6.11, 4.0.0 through 4.1.6, and 4.2.0 through 4.2.1 of Apache CXF.

Details

Module Info

Vulnerability Info

This Medium-severity vulnerability is found in the cxf-rt-rs-security-oauth2 package in versions 3.1.7 through 3.6.11, 4.0.0 through 4.1.6, and 4.2.0 through 4.2.1 of Apache CXF.

Token endpoints built on AbstractTokenService (such as AccessTokenService and TokenRevocationService) resolve the calling client from request data before any client authentication has succeeded. The client identifier comes from the client_id form parameter, or from the user name of an HTTP Basic Authorization header:

protected String retrieveClientId(MultivaluedMap<String, String> params) {
    String clientId = params.getFirst(OAuthConstants.CLIENT_ID);
    if (clientId == null) {
        clientId = (String)getMessageContext().get(OAuthConstants.CLIENT_ID);
    }
    if (clientId == null && clientIdProvider != null) {
        clientId = clientIdProvider.getClientId(getMessageContext());
    }
    return clientId;
}

That value is passed to getClient. When no registered client matches it, as is the case for an arbitrary attacker-chosen value, the raw identifier is concatenated into a warning log message:

protected Client getClient(String clientId, String clientSecret, MultivaluedMap<String, String> params) {
    if (clientId == null) {
        reportInvalidRequestError("Client ID is null");
        return null;
    }
    Client client = null;
    try {
        client = getValidClient(clientId, clientSecret, params);
    } catch (OAuthServiceException ex) {
        LOG.warning("No valid client found for clientId: " + clientId);
        if (ex.getError() != null) {
            reportInvalidClient(ex.getError());
            return null;
        }
    }
    if (client == null) {
        LOG.warning("No valid client found for clientId: " + clientId);
        reportInvalidClient();
    }
    return client;
}

No control characters are removed or escaped before the value reaches the logger. An unauthenticated attacker can therefore send a token request such as client_id=unknown%0d%0a<forged log line> with any client_secret, and the CR/LF sequence starts a new line in line-oriented log files. The injected text can impersonate legitimate log records (for example successful token grants or other users' activity), hide or confuse evidence of an attack during incident response, and feed misleading data to log monitoring and SIEM tooling that parses these files.

Mitigation

Only recent versions of Apache CXF are community-supported. The affected 3.4.x and 3.5.x lines are End-of-Life and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • Guanping Zhang (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2026-50629
PROJECT Affected
Apache CXF
Versions Affected
>=3.1.7 <3.6.12, >=4.0.0 <4.1.7, >=4.2.0 <4.2.2
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
September 29, 2026
Category
Log Injection
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.