Severity: low 

Affected versions:

- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.3
- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.0.0 before 4.1.8
- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 3.6.12

Description:

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization 
code can be redeemed an unlimited number of times due to a flaw in the 
implementation of the removeCodeGrant functionality. This violates the RFC 
requirement that "The authorization code MUST NOT be used more than once." 
Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which 
fix this issue.

Credit:

Guanping Zhang reported this vulnerability (finder)

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-68079

Reply via email to