PT-2026-108866 · Apache · Apache Cxf
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Apache CXF versions prior to 4.2.4
Apache CXF versions prior to 4.1.9
Apache CXF versions prior to 3.6.13
Description
The STSTokenValidator and Security Token Service (STS) cached validated security tokens using a non-cryptographic 32-bit hash generated by
Java Arrays.hashCode/hashCode(). Because the system treated a cache hit as confirmation that a token was already validated, an attacker could create a token, such as a UsernameToken or a self-signed SAML Assertion, with a hash that collides with an existing cached entry. This allows the attacker to bypass password validation, signature trust verification, or STS calls, enabling them to authenticate as another user and potentially obtain STS-signed tokens for that identity through token validation or renewal.Recommendations
Upgrade to version 4.2.4.
Upgrade to version 4.1.9.
Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Cxf