Feed/CVE-2026-50630
CVE-2026-50630MEDIUMCVSS 6.5

CVE-2026-50630

Published Jun 12, 2026·Updated Aug 20, 2026

NVD Description

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Affected Packages (1)

org.apache.cxf:cxf-rt-rs-security-oauth2MAVEN
From 4.2.0
Fixed in 4.2.2

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free