PT-2026-108815 · Apache · Apache Cxf
CVE-2026-73179
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Apache CXF versions prior to 4.2.4
Apache CXF versions prior to 4.1.9
Apache CXF versions prior to 3.6.13
Description
Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider allows a remote attacker to obtain multiple valid access tokens from a single authorization code. This occurs via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ COMMITTED isolation. READ COMMITTED is a database isolation level that ensures a transaction can only read data that has been committed before the read operation begins.
Recommendations
Upgrade to version 4.2.4.
Upgrade to version 4.1.9.
Upgrade to version 3.6.13.
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Cxf