PT-2026-80247 · Maven · Org.Apache.Cxf:Cxf-Rt-Rs-Security-Oauth2

Published

2026-06-12

·

Updated

2026-06-12

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-83R6-96M8-R52P

Affected Products

Org.Apache.Cxf:Cxf-Rt-Rs-Security-Oauth2