PT-2026-108866 · Apache · Apache Cxf

·

CVE-2026-97468

·

Published

2026-10-09

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache CXF versions prior to 4.2.4 Apache CXF versions prior to 4.1.9 Apache CXF versions prior to 3.6.13
Description The STSTokenValidator and Security Token Service (STS) cached validated security tokens using a non-cryptographic 32-bit hash generated by Java Arrays.hashCode/hashCode(). Because the system treated a cache hit as confirmation that a token was already validated, an attacker could create a token, such as a UsernameToken or a self-signed SAML Assertion, with a hash that collides with an existing cached entry. This allows the attacker to bypass password validation, signature trust verification, or STS calls, enabling them to authenticate as another user and potentially obtain STS-signed tokens for that identity through token validation or renewal.
Recommendations Upgrade to version 4.2.4. Upgrade to version 4.1.9. Upgrade to version 3.6.13.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97468

Affected Products

Apache Cxf