CVE-2026-63687
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.
An Authorization Bypass vulnerability (CVE-2026-63687) has been identified in the JwtRequestCodeFilter of the Apache CXF OAuth 2.0 module, which allows attackers who can produce a validly signed request object JWT to replace the code_challenge, code_challenge_method, nonce, and state values sent in the outer authorization request, undermining PKCE integrity, CSRF protection, and OpenID Connect replay protection.
Per OWASP: Access control, sometimes called authorization, is how a web application grants access to content and functions to some users and not others. These checks are performed after authentication, and govern what ‘authorized’ users are allowed to do.
This issue affects versions before 3.6.12, 4.0.0 through 4.1.7, and 4.2.0 through 4.2.2 of Apache CXF.
Details
Module Info
- Product: Apache CXF
- Affected packages:
org.apache.cxf:cxf-rt-rs-security-oauth2 - Affected versions: <3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3
- GitHub repository: https://github.com/apache/cxf
- Published packages: https://central.sonatype.com/artifact/org.apache.cxf/cxf-rt-rs-security-oauth2
- Package manager: Maven
- Fixed in:
- Apache CXF 3.6.12, 4.1.8, 4.2.3 (OSS)
- NES for Apache CXF v3.5.13, v3.4.12
Vulnerability Info
This Critical-severity vulnerability is found in the org.apache.cxf:cxf-rt-rs-security-oauth2 package in versions before 3.6.12, 4.0.0 through 4.1.7, and 4.2.0 through 4.2.2 of Apache CXF. CISA-ADP rates it 9.1 on CVSS v3.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Apache CXF supports the OAuth 2.0 JWT-Secured Authorization Request (JAR) pattern, in which a client passes its authorization parameters inside a signed (and optionally encrypted) request object JWT, either inline through the request parameter or by reference through request_uri. The JwtRequestCodeFilter authorization request filter verifies the JWT signature, checks the issuer, client_id, and response_type, and then merges the JWT claims into the authorization parameter map that the rest of the authorization code flow consumes.
The merge copies every claim of the JWT into the parameter map with putSingle, which replaces any value already present from the outer HTTP request. No claim is excluded, so a JWT carrying code_challenge, code_challenge_method, nonce, or state silently overrides the values the outer request supplied:
MultivaluedMap<String, String> newParams = new MetadataMap<>(params);
Map<String, Object> claimsMap = claims.asMap();
for (Map.Entry<String, Object> entry : claimsMap.entrySet()) {
String key = entry.getKey();
Object value = entry.getValue();
if (value instanceof Map) {
Map<String, Object> map = CastUtils.cast((Map<?, ?>)value);
value = jsonHandler.toJson(map);
} else if (value instanceof List) {
List<Object> list = CastUtils.cast((List<?>)value);
value = jsonHandler.toJson(list);
}
newParams.putSingle(key, value.toString());
}
return newParams;
The outer request's PKCE, state, and nonce values bind the authorization flow to the legitimate client's session, so a request object should never be able to replace them. Because CXF lets the JWT win, anyone able to produce a validly signed request object for a client can substitute their own PKCE code_challenge and code_challenge_method, which breaks the binding between the authorization code and the legitimate client's code_verifier and enables authorization code interception and injection. The same override lets the attacker replace state, defeating the client's CSRF protection, and nonce, defeating OpenID Connect ID token replay protection.
This vulnerability was introduced in 2014 with Apache CXF 3.0.3.
Mitigation
Only recent versions of Apache CXF are community-supported. The 3.5.x line was already End-of-Life when this CVE was published and will not receive public updates to address this issue.
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Guanping Zhang (finder)