Severity: important 

Affected versions:

- Apache CXF 4.2.0 before 4.2.4
- Apache CXF 4.0.0 before 4.1.9
- Apache CXF before 3.6.13

Description:

Apache CXF's STSTokenValidator and Security Token Service (STS) cached 
validated security tokens under a non-cryptographic 32-bit hash of the token 
(Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the 
presented token had already been validated. An attacker could craft a token 
(for example a UsernameToken or a self-signed SAML Assertion) whose hash 
collides with a cached entry. The token would then be accepted without password 
validation, signature trust verification or a call to the STS. This could let 
the attacker authenticate as another user and, through STS token validation or 
renewal, obtain STS-signed tokens for that identity.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.

Credit:

MopMonk-AI (finder)

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-97468

Reply via email to