PT-2026-108812 · Apache · Apache Cxf

CVE-2026-107938

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 4.2.4 Apache CXF versions prior to 4.1.9 Apache CXF versions prior to 3.6.13
Description The Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) fails to verify that the hostname in the server TLS certificate matches the host being called. This issue affects both HTTP/1.1 and HTTP/2 protocols, occurring even when disableCNCheck is set to its default value of false. While the certificate chain is validated against the trust store, the identity of the endpoint is not confirmed. A network attacker capable of intercepting traffic could use a trusted certificate for a domain under their control to impersonate the target service, allowing them to read or modify exchanged messages and credentials.
Recommendations Upgrade to version 4.2.4. Upgrade to version 4.1.9. Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-107938

Affected Products

Apache Cxf