PT-2026-108815 · Apache · Apache Cxf

CVE-2026-73179

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 4.2.4 Apache CXF versions prior to 4.1.9 Apache CXF versions prior to 3.6.13
Description Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider allows a remote attacker to obtain multiple valid access tokens from a single authorization code. This occurs via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ COMMITTED isolation. READ COMMITTED is a database isolation level that ensures a transaction can only read data that has been committed before the read operation begins.
Recommendations Upgrade to version 4.2.4. Upgrade to version 4.1.9. Upgrade to version 3.6.13.

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73179

Affected Products

Apache Cxf