CVE-2026-57817
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.
An Insufficient Verification of Data Authenticity vulnerability (CVE-2026-57817) has been identified in the OpenID Connect relying-party (RP) support of the Apache CXF cxf-rt-rs-security-sso-oidc module, which allows attackers to perform Authorization Code Substitution (injection) attacks against an RP that uses the OIDC Hybrid Flow. The OpenID Connect Core 1.0 specification requires the RP to validate the c_hash claim of the ID token in the Hybrid Flow. The CXF IdTokenReader only enforced this when the requireCodeHash option was explicitly enabled, so an RP talking to a non-compliant or misconfigured Identity Provider (IdP) that omits c_hash accepts an ID token that is not bound to the authorization code it received.
Per OWASP: Confirmation of the user's identity, authentication, and session management is critical to protect against authentication-related attacks.
This issue affects all versions prior to 3.6.12, versions 4.0.0 through 4.1.7, and versions 4.2.0 through 4.2.2 of Apache CXF.
Details
Module Info
- Product: Apache CXF
- Affected packages:
org.apache.cxf:cxf-rt-rs-security-sso-oidc - Affected versions: <3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3
- GitHub repository: https://github.com/apache/cxf
- Published packages: https://central.sonatype.com/artifact/org.apache.cxf/cxf-rt-rs-security-sso-oidc
- Package manager: Maven
- Fixed in:
- OSS Apache CXF 3.6.12, 4.1.8, 4.2.3
- NES for Apache CXF v3.5.13, v3.4.12
Vulnerability Info
This High-severity vulnerability is found in the org.apache.cxf:cxf-rt-rs-security-sso-oidc package in all versions prior to 3.6.12, versions 4.0.0 through 4.1.7, and versions 4.2.0 through 4.2.2 of Apache CXF.
In the OIDC Hybrid Flow (response_type of code id_token or code id_token token), the IdP returns an ID token together with an authorization code on the front channel. The c_hash claim inside the signed ID token is what binds that ID token to the specific code. When the CXF RP redeems the code, OidcClientCodeRequestFilter passes the authorization code from the request to IdTokenReader:
IdToken idToken = idTokenReader.getIdToken(at,
requestParams.getFirst(OAuthConstants.AUTHORIZATION_CODE_VALUE),
getConsumer());IdTokenReader then validates the code hash, but only treats a missing c_hash as an error when requireCodeHash is set, and that flag defaults to false. Nothing in this path takes the flow's response_type into account:
public class IdTokenReader extends OidcClaimsValidator {
private boolean requireAtHash = true;
private boolean requireCodeHash;
// ...
public JwtToken getIdJwtToken(ClientAccessToken at, String code, Consumer client) {
String idJwtToken = at.getParameters().get(OidcUtils.ID_TOKEN);
JwtToken jwt = getIdJwtToken(idJwtToken, client);
OidcUtils.validateAccessTokenHash(at, jwt, requireAtHash);
OidcUtils.validateCodeHash(code, jwt, requireCodeHash);
return jwt;
}
// ...
}OidcUtils.validateCodeHash skips the check entirely when the claim is absent and required is false:
public static void validateCodeHash(String code, JwtToken jwt, boolean required) {
String hashClaim = (String)jwt.getClaims().getClaim(IdToken.AUTH_CODE_HASH_CLAIM);
if (hashClaim == null && required) {
throw new OAuthServiceException("Invalid hash");
}
if (hashClaim != null) {
validateHash(code,
(String)jwt.getClaims().getClaim(IdToken.AUTH_CODE_HASH_CLAIM),
jwt.getJwsHeaders().getSignatureAlgorithm());
}
}The IdP-side IdTokenResponseFilter in the same module also did not forward the response_type to the client token response, so the RP had no signal that it was in a hybrid flow. As a result, with default settings a Hybrid Flow RP integrated with an IdP that omits c_hash accepts any validly signed ID token without checking that it belongs to the authorization code being redeemed. An attacker who can substitute a different authorization code into the flow can therefore have it redeemed without the RP detecting that the ID token and the code do not match.
Mitigation
Only recent versions of Apache CXF receive community support. Older lines are End-of-Life and will not receive public updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Guanping Zhang (finder)