Severity: low 

Affected versions:

- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.4
- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.0.0 before 4.1.9
- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 3.6.13

Description:

Improper enforcement of single-use authorization code semantics in the JPA 
OAuth2 authorization code grant provider in Apache CXFallows a remote attacker 
to obtain multiple valid access tokens from a single authorization code via 
concurrent token exchange requests that race the non-atomic find-then-delete 
operation against a shared relational database under READ_COMMITTED isolation. 
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fixes this issue.

Credit:

Guanping Zhang reported this vulnerability (finder)

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-73179

Reply via email to