Feed/CVE-2026-50628
CVE-2026-50628CRITICALCVSS 9.8

CVE-2026-50628

Published Jun 12, 2026·Updated Aug 20, 2026

NVD Description

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Packages (1)

org.apache.cxf:cxf-rt-rs-security-oauth2MAVEN
From 4.2.0
Fixed in 4.2.2

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free