Messages by Date
-
2026/09/17
[jira] [Resolved] (CXF-9245) Race Condition in ServerLifeCycleManagerImpl#stopServer()
Andriy Redko (Jira)
-
2026/09/16
[jira] [Updated] (CXF-9245) Race Condition in ServerLifeCycleManagerImpl#stopServer()
Andriy Redko (Jira)
-
2026/09/16
[jira] [Updated] (CXF-9245) Race Condition in ServerLifeCycleManagerImpl#stopServer()
Andriy Redko (Jira)
-
2026/09/15
[jira] [Commented] (CXF-9245) Race Condition in ServerLifeCycleManagerImpl#stopServer()
Andriy Redko (Jira)
-
2026/09/09
[jira] [Resolved] (CXF-9246) Race condition in threaded ConnectorServerFactory
Andriy Redko (Jira)
-
2026/09/09
[jira] [Commented] (CXF-9246) Race condition in threaded ConnectorServerFactory
Andriy Redko (Jira)
-
2026/09/08
[jira] [Created] (CXF-9246) Race condition in threaded ConnectorServerFactory
ytwang (Jira)
-
2026/08/31
[jira] [Assigned] (CXF-9245) Race Condition in ServerLifeCycleManagerImpl#stopServer()
Andriy Redko (Jira)
-
2026/08/31
[jira] [Created] (CXF-9245) Race Condition in ServerLifeCycleManagerImpl#stopServer()
Benjamin Marwell (Jira)
-
2026/08/25
[jira] [Commented] (CXF-8913) Avoid 3rd party maven repository for OpenSAML
Colm O hEigeartaigh (Jira)
-
2026/08/25
[jira] [Resolved] (CXF-8913) Avoid 3rd party maven repository for OpenSAML
Colm O hEigeartaigh (Jira)
-
2026/08/25
[jira] [Commented] (CXF-8913) Avoid 3rd party maven repository for OpenSAML
Claus Ibsen (Jira)
-
2026/08/25
[jira] [Commented] (CXF-8913) Avoid 3rd party maven repository for OpenSAML
Colm O hEigeartaigh (Jira)
-
2026/08/25
[jira] [Commented] (CXF-8913) Avoid 3rd party maven repository for OpenSAML
Thomas Beckers (Jira)
-
2026/08/24
[jira] [Resolved] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Andriy Redko (Jira)
-
2026/08/24
[jira] [Resolved] (CXF-9241) ImplicitConfidentialGrantService violates RFC 6749 §4.2.2 by issuing Refresh Tokens in the Implicit Flow
Colm O hEigeartaigh (Jira)
-
2026/08/21
[jira] [Updated] (CXF-9241) ImplicitConfidentialGrantService violates RFC 6749 §4.2.2 by issuing Refresh Tokens in the Implicit Flow
Colm O hEigeartaigh (Jira)
-
2026/08/21
[jira] [Closed] (CXF-9236) Hawk validator: nonce/replay protection silently disabled by default (NonceVerifier never wired) — fail closed or auto-wire
Colm O hEigeartaigh (Jira)
-
2026/08/21
[jira] [Created] (CXF-9244) Remove Hawk functionality
Colm O hEigeartaigh (Jira)
-
2026/08/21
[jira] [Updated] (CXF-9241) ImplicitConfidentialGrantService violates RFC 6749 §4.2.2 by issuing Refresh Tokens in the Implicit Flow
Colm O hEigeartaigh (Jira)
-
2026/08/21
[jira] [Assigned] (CXF-9241) ImplicitConfidentialGrantService violates RFC 6749 §4.2.2 by issuing Refresh Tokens in the Implicit Flow
Colm O hEigeartaigh (Jira)
-
2026/08/18
[jira] [Resolved] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Freeman Yue Fang (Jira)
-
2026/08/18
[jira] [Updated] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Freeman Yue Fang (Jira)
-
2026/08/15
[jira] [Created] (CXF-9243) AuthorizationCodeGrantHandler consumes (burns) authorization code before performing validation (PKCE/redirect_uri), causing availability DoS on legitimate retries
Guanping Zhang (Jira)
-
2026/08/15
[jira] [Created] (CXF-9242) JwtAccessTokenValidator accepts absent `typ` header; OIDC IdP issues id_tokens without `typ`, enabling token confusion in misconfigured RS
Guanping Zhang (Jira)
-
2026/08/14
[jira] [Assigned] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Freeman Yue Fang (Jira)
-
2026/08/14
[jira] [Commented] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/13
[jira] [Commented] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/08/13
[jira] [Assigned] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Andriy Redko (Jira)
-
2026/08/13
[jira] [Updated] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Andriy Redko (Jira)
-
2026/08/13
[jira] [Commented] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/08/13
[jira] [Created] (CXF-9241) ImplicitConfidentialGrantService violates RFC 6749 §4.2.2 by issuing Refresh Tokens in the Implicit Flow
Guanping Zhang (Jira)
-
2026/08/13
[jira] [Assigned] (CXF-9237) JCacheOAuthDataProvider.createCache() sets no expiry policy — cache entries (incl. expired tokens) are never evicted
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Updated] (CXF-9237) JCacheOAuthDataProvider.createCache() sets no expiry policy — cache entries (incl. expired tokens) are never evicted
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Commented] (CXF-9237) JCacheOAuthDataProvider.createCache() sets no expiry policy — cache entries (incl. expired tokens) are never evicted
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Updated] (CXF-9237) JCacheOAuthDataProvider.createCache() sets no expiry policy — cache entries (incl. expired tokens) are never evicted
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Assigned] (CXF-9237) JCacheOAuthDataProvider.createCache() sets no expiry policy — cache entries (incl. expired tokens) are never evicted
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Resolved] (CXF-9239) JoseSessionTokenProvider accepts JWE-only (no JWS) session tokens — enforce encrypt-then-sign or warn/document the integrity gap
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Assigned] (CXF-9239) JoseSessionTokenProvider accepts JWE-only (no JWS) session tokens — enforce encrypt-then-sign or warn/document the integrity gap
Colm O hEigeartaigh (Jira)
-
2026/08/13
[jira] [Resolved] (CXF-9240) OAuthJSONProvider.appendJsonPair() does not escape JSON string values — output injection / malformed JSON in introspect & token responses
Colm O hEigeartaigh (Jira)
-
2026/08/12
[jira] [Updated] (CXF-9240) OAuthJSONProvider.appendJsonPair() does not escape JSON string values — output injection / malformed JSON in introspect & token responses
Colm O hEigeartaigh (Jira)
-
2026/08/12
[jira] [Updated] (CXF-9240) OAuthJSONProvider.appendJsonPair() does not escape JSON string values — output injection / malformed JSON in introspect & token responses
Colm O hEigeartaigh (Jira)
-
2026/08/12
[jira] [Assigned] (CXF-9240) OAuthJSONProvider.appendJsonPair() does not escape JSON string values — output injection / malformed JSON in introspect & token responses
Colm O hEigeartaigh (Jira)
-
2026/08/10
[jira] [Created] (CXF-9238) AbstractAccessTokenValidator validation cache evicts ALL entries via clear() on overflow — replace with LRU to avoid cache-thrash
Guanping Zhang (Jira)
-
2026/08/10
[jira] [Created] (CXF-9240) OAuthJSONProvider.appendJsonPair() does not escape JSON string values — output injection / malformed JSON in introspect & token responses
Guanping Zhang (Jira)
-
2026/08/10
[jira] [Created] (CXF-9239) JoseSessionTokenProvider accepts JWE-only (no JWS) session tokens — enforce encrypt-then-sign or warn/document the integrity gap
Guanping Zhang (Jira)
-
2026/08/09
[jira] [Commented] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Andriy Redko (Jira)
-
2026/08/09
[jira] [Updated] (CXF-9236) Hawk validator: nonce/replay protection silently disabled by default (NonceVerifier never wired) — fail closed or auto-wire
Guanping Zhang (Jira)
-
2026/08/09
[jira] [Created] (CXF-9237) JCacheOAuthDataProvider.createCache() sets no expiry policy — cache entries (incl. expired tokens) are never evicted
Guanping Zhang (Jira)
-
2026/08/09
[jira] [Created] (CXF-9236) Hawk validator: nonce/replay protection silently disabled by default (NonceVerifier never wired) — fail closed or auto-wire
Guanping Zhang (Jira)
-
2026/08/09
[jira] [Commented] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Guanping Zhang (Jira)
-
2026/08/07
[jira] [Comment Edited] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/06
[jira] [Comment Edited] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/06
[jira] [Commented] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/05
[jira] [Comment Edited] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Freeman Yue Fang (Jira)
-
2026/08/05
[jira] [Commented] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Freeman Yue Fang (Jira)
-
2026/08/05
[jira] [Resolved] (CXF-9234) Concurrent DynamicClientFactory.createClient for the same WSDL url corrupts the cached schema DOM and spins forever at 100% CPU
Freeman Yue Fang (Jira)
-
2026/08/05
[jira] [Updated] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Commented] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Updated] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Updated] (CXF-9235) Invocation.Builder.property() settings ignored by HTTP transport for set.content.type.for.empty.request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Updated] (CXF-9235) set.content.type.for.empty.request seems to be ignored in DELETE request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Updated] (CXF-9235) set.content.type.for.empty.request seems to be ignored in DELETE request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Updated] (CXF-9235) set.content.type.for.empty.request seems to be ignored in DELETE request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Updated] (CXF-9235) set.content.type.for.empty.request seems to be ignored in DELETE request
Neena Jacob (Jira)
-
2026/08/04
[jira] [Created] (CXF-9235) set.content.type.for.empty.request seems to be ignored in DELETE request
Neena Jacob (Jira)
-
2026/08/01
[jira] [Updated] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/08/01
[jira] [Comment Edited] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/08/01
[jira] [Commented] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/08/01
[jira] [Updated] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/29
[jira] [Updated] (CXF-9035) Fix java.util.ConcurrentModificationException at org.apache.cxf.message.MessageImpl.calcContextCache
Andriy Redko (Jira)
-
2026/07/28
[jira] [Updated] (CXF-9126) LEAKs reported when running cxf-systests-transport-netty with 'paranoid' detection level
Andriy Redko (Jira)
-
2026/07/28
[jira] [Updated] (CXF-9220) Remove Apache Derby since it is retired
Andriy Redko (Jira)
-
2026/07/28
[jira] [Updated] (CXF-9072) NewCookieHeaderProvider does not support SameSite attribute on cookies
Andriy Redko (Jira)
-
2026/07/28
[jira] [Updated] (CXF-9109) MAX_PER_HOST_CONNECTIONS does not work
Andriy Redko (Jira)
-
2026/07/28
[jira] [Updated] (CXF-9061) Update documentation to use Jakarta namespaces as well (where appropriate)
Andriy Redko (Jira)
-
2026/07/28
[jira] [Assigned] (CXF-9234) Concurrent DynamicClientFactory.createClient for the same WSDL url corrupts the cached schema DOM and spins forever at 100% CPU
Freeman Yue Fang (Jira)
-
2026/07/28
[jira] [Created] (CXF-9234) Concurrent DynamicClientFactory.createClient for the same WSDL url corrupts the cached schema DOM and spins forever at 100% CPU
David Richter (Jira)
-
2026/07/27
[jira] [Comment Edited] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/27
[jira] [Commented] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/27
[jira] [Comment Edited] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/27
[jira] [Comment Edited] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/27
[jira] [Commented] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/27
[jira] [Created] (CXF-9233) AbstractLoggingInterceptor.LIVE_LOGGING_PROP already set in the message properties, so RESP_OUT log is disable :(
Valentino Porta (Jira)
-
2026/07/23
[jira] [Resolved] (CXF-9223) completeAudienceMatch=false defaults to prefix matching for audience validation, widening resource access
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Commented] (CXF-9223) completeAudienceMatch=false defaults to prefix matching for audience validation, widening resource access
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Updated] (CXF-9223) completeAudienceMatch=false defaults to prefix matching for audience validation, widening resource access
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Updated] (CXF-9223) completeAudienceMatch=false defaults to prefix matching for audience validation, widening resource access
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Assigned] (CXF-9223) completeAudienceMatch=false defaults to prefix matching for audience validation, widening resource access
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Assigned] (CXF-9224) Authorization responses omit RFC 9207 iss parameter, exposing clients to OAuth mix-up attacks
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Updated] (CXF-9225) OIDC RP does not enforce nonce validation for Implicit/Hybrid flows
Colm O hEigeartaigh (Jira)
-
2026/07/23
[jira] [Resolved] (CXF-9225) OIDC RP does not enforce nonce validation for Implicit/Hybrid flows
Colm O hEigeartaigh (Jira)
-
2026/07/22
[jira] [Commented] (CXF-8998) cxf-codegen-plugin - debug output velocity
Freeman Yue Fang (Jira)
-
2026/07/22
[jira] [Assigned] (CXF-9224) Authorization responses omit RFC 9207 iss parameter, exposing clients to OAuth mix-up attacks
Colm O hEigeartaigh (Jira)
-
2026/07/22
[jira] [Updated] (CXF-9225) OIDC RP does not enforce nonce validation for Implicit/Hybrid flows
Colm O hEigeartaigh (Jira)
-
2026/07/22
[jira] [Assigned] (CXF-9225) OIDC RP does not enforce nonce validation for Implicit/Hybrid flows
Colm O hEigeartaigh (Jira)
-
2026/07/22
[jira] [Resolved] (CXF-8780) 3.5.4 Version - org.apache.cxf.common.util.ReflectionUtil.getDeclaredMethod no such method error
Colm O hEigeartaigh (Jira)
-
2026/07/21
[jira] [Commented] (CXF-8998) cxf-codegen-plugin - debug output velocity
Karl Heinz Marbaise (Jira)
-
2026/07/21
[jira] [Reopened] (CXF-8998) cxf-codegen-plugin - debug output velocity
Karl Heinz Marbaise (Jira)
-
2026/07/13
[jira] [Created] (CXF-9232) Implement JTI/Assertion-ID replay cache for SAML and JWT bearer grants (Close //TODO)
Guanping Zhang (Jira)
-
2026/07/10
[jira] [Commented] (CXF-9231) sign/verify and encrypt/decrypt soap payload with PQC compatible Alg
Freeman Yue Fang (Jira)
-
2026/07/10
[jira] [Assigned] (CXF-9231) sign/verify and encrypt/decrypt soap payload with PQC compatible Alg
Freeman Yue Fang (Jira)
-
2026/07/10
[jira] [Created] (CXF-9231) sign/verify and encrypt/decrypt soap payload with PQC compatible Alg
Freeman Yue Fang (Jira)
-
2026/07/10
[jira] [Resolved] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/10
[jira] [Updated] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/09
[jira] [Comment Edited] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/09
[jira] [Comment Edited] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/09
[jira] [Commented] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/09
[jira] [Resolved] (CXF-9230) Update to Spring Boot 4.1 release line
Andriy Redko (Jira)
-
2026/07/06
[jira] [Created] (CXF-9230) Update to Spring Boot 4.1 release line
Andriy Redko (Jira)
-
2026/07/06
[jira] [Commented] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/06
[jira] [Created] (CXF-9228) Post-Quantum Cryptography (PQC) Readiness
Freeman Yue Fang (Jira)
-
2026/07/06
[jira] [Assigned] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/06
[jira] [Created] (CXF-9229) Prove that CXF can support Post-Quantum Cryptography TLS using the X25519MLKEM768 hybrid key-encapsulation mechanism (KEM).
Freeman Yue Fang (Jira)
-
2026/07/06
[jira] [Resolved] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Freeman Yue Fang (Jira)
-
2026/07/05
[jira] [Resolved] (CXF-9161) Some of the OIDCFlowTest fail with timeout (JPA only) when HttpClient instance is shared
Andriy Redko (Jira)
-
2026/07/03
[jira] [Updated] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Colm O hEigeartaigh (Jira)
-
2026/07/02
[jira] [Resolved] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Freeman Yue Fang (Jira)
-
2026/06/26
[jira] [Commented] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Fabio Burzigotti (Jira)
-
2026/06/26
[jira] [Commented] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Freeman Yue Fang (Jira)
-
2026/06/26
[jira] [Commented] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Fabio Burzigotti (Jira)
-
2026/06/26
[jira] [Resolved] (CXF-9222) partialMatchScopeValidation allows prefix-based scope escalation (e.g., read grants readwrite)
Colm O hEigeartaigh (Jira)
-
2026/06/26
[jira] [Updated] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Freeman Yue Fang (Jira)
-
2026/06/26
[jira] [Created] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Freeman Yue Fang (Jira)
-
2026/06/26
[jira] [Assigned] (CXF-9227) CXF 4.1.7 regression: more SecurityManager permission requirements
Freeman Yue Fang (Jira)
-
2026/06/26
[jira] [Commented] (CXF-9222) partialMatchScopeValidation allows prefix-based scope escalation (e.g., read grants readwrite)
Colm O hEigeartaigh (Jira)
-
2026/06/26
[jira] [Updated] (CXF-9222) partialMatchScopeValidation allows prefix-based scope escalation (e.g., read grants readwrite)
Colm O hEigeartaigh (Jira)
-
2026/06/26
[jira] [Assigned] (CXF-9222) partialMatchScopeValidation allows prefix-based scope escalation (e.g., read grants readwrite)
Colm O hEigeartaigh (Jira)
-
2026/06/25
[jira] [Commented] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Reto Weiss (Jira)
-
2026/06/25
[jira] [Updated] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Freeman Yue Fang (Jira)
-
2026/06/25
[jira] [Updated] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Freeman Yue Fang (Jira)
-
2026/06/25
[jira] [Commented] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Freeman Yue Fang (Jira)
-
2026/06/25
[jira] [Assigned] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Freeman Yue Fang (Jira)
-
2026/06/24
[jira] [Updated] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Reto Weiss (Jira)
-
2026/06/24
[jira] [Created] (CXF-9226) Proxy authentication fails with IllegalStateException instead of HTTPException (407)
Reto Weiss (Jira)
-
2026/06/24
[jira] [Resolved] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Andriy Redko (Jira)
-
2026/06/24
[jira] [Updated] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Andriy Redko (Jira)
-
2026/06/24
[jira] [Assigned] (CXF-9224) Authorization responses omit RFC 9207 iss parameter, exposing clients to OAuth mix-up attacks
Colm O hEigeartaigh (Jira)
-
2026/06/24
[jira] [Assigned] (CXF-9224) Authorization responses omit RFC 9207 iss parameter, exposing clients to OAuth mix-up attacks
Colm O hEigeartaigh (Jira)
-
2026/06/20
[jira] [Updated] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Andriy Redko (Jira)
-
2026/06/20
[jira] [Updated] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Andriy Redko (Jira)
-
2026/06/20
[jira] [Assigned] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Andriy Redko (Jira)
-
2026/06/19
[jira] [Comment Edited] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/19
[jira] [Comment Edited] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/19
[jira] [Comment Edited] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/19
[jira] [Commented] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/19
[jira] [Updated] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/19
[jira] [Created] (CXF-9225) OIDC RP does not enforce nonce validation for Implicit/Hybrid flows
Guanping Zhang (Jira)
-
2026/06/19
[jira] [Created] (CXF-9224) Authorization responses omit RFC 9207 iss parameter, exposing clients to OAuth mix-up attacks
Guanping Zhang (Jira)
-
2026/06/19
[jira] [Created] (CXF-9223) completeAudienceMatch=false defaults to prefix matching for audience validation, widening resource access
Guanping Zhang (Jira)
-
2026/06/19
[jira] [Created] (CXF-9222) partialMatchScopeValidation allows prefix-based scope escalation (e.g., read grants readwrite)
Guanping Zhang (Jira)
-
2026/06/19
[jira] [Updated] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Guanping Zhang (Jira)
-
2026/06/19
[jira] [Created] (CXF-9221) JCache providers use inverted isExpired() logic causing expired tokens/codes to never be evicted
Guanping Zhang (Jira)
-
2026/06/18
[jira] [Commented] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/18
[jira] [Updated] (CXF-8926) MTOM - Lock while processing attachment
mircea (Jira)
-
2026/06/16
[jira] [Created] (CXF-9220) Remove Apache Derby since it is retired
Andriy Redko (Jira)
-
2026/06/16
[jira] [Resolved] (CXF-9219) cxf-bom manages dependencies for 4.x that no longer exist or are not published
Andriy Redko (Jira)
-
2026/06/10
[jira] [Assigned] (CXF-9219) cxf-bom manages dependencies for 4.x that no longer exist or are not published
Andriy Redko (Jira)
-
2026/06/10
[jira] [Updated] (CXF-9219) cxf-bom manages dependencies for 4.x that no longer exist or are not published
Andriy Redko (Jira)
-
2026/06/10
[jira] [Created] (CXF-9219) cxf-bom manages dependencies for 4.x that no longer exist or are not published
James Hutton (Jira)
-
2026/06/09
[jira] [Updated] (CXF-8926) MTOM - Lock while processing attachment
Freeman Yue Fang (Jira)
-
2026/06/09
[jira] [Commented] (CXF-8926) MTOM - Lock while processing attachment
Freeman Yue Fang (Jira)
-
2026/06/09
[jira] [Assigned] (CXF-8926) MTOM - Lock while processing attachment
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9161) Some of the OIDCFlowTest fail with timeout (JPA only) when HttpClient instance is shared
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9109) MAX_PER_HOST_CONNECTIONS does not work
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9072) NewCookieHeaderProvider does not support SameSite attribute on cookies
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9126) LEAKs reported when running cxf-systests-transport-netty with 'paranoid' detection level
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9061) Update documentation to use Jakarta namespaces as well (where appropriate)
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9061) Update documentation to use Jakarta namespaces as well (where appropriate)
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9035) Fix java.util.ConcurrentModificationException at org.apache.cxf.message.MessageImpl.calcContextCache
Freeman Yue Fang (Jira)
-
2026/06/04
[jira] [Updated] (CXF-9035) Fix java.util.ConcurrentModificationException at org.apache.cxf.message.MessageImpl.calcContextCache
Freeman Yue Fang (Jira)
-
2026/06/02
[jira] [Resolved] (CXF-9213) RetryStrategy is a stateful class whose objects shouldn't be reused
Freeman Yue Fang (Jira)
-
2026/06/02
[jira] [Commented] (CXF-9111) Default behavior for "multipart/form-data" requests not standard-conform
Freeman Yue Fang (Jira)
-
2026/06/02
[jira] [Commented] (CXF-9111) Default behavior for "multipart/form-data" requests not standard-conform
Carsten Teich (Jira)
-
2026/06/01
[jira] [Commented] (CXF-9111) Default behavior for "multipart/form-data" requests not standard-conform
Freeman Yue Fang (Jira)
-
2026/06/01
[jira] [Commented] (CXF-9111) Default behavior for "multipart/form-data" requests not standard-conform
Carsten Teich (Jira)
-
2026/06/01
[jira] [Commented] (CXF-9111) Default behavior for "multipart/form-data" requests not standard-conform
Freeman Yue Fang (Jira)
-
2026/06/01
[jira] [Commented] (CXF-9111) Default behavior for "multipart/form-data" requests not standard-conform
Carsten Teich (Jira)
-
2026/06/01
[jira] [Commented] (CXF-9218) Respect configured ProxySelector instead of hard-wiring system proxy properties
Matthias Pretzer (Jira)
-
2026/05/29
[jira] [Resolved] (CXF-9218) Respect configured ProxySelector instead of hard-wiring system proxy properties
Freeman Yue Fang (Jira)
-
2026/05/29
[jira] [Resolved] (CXF-9129) Chunked attachment streaming not working when using ws-security
Freeman Yue Fang (Jira)
-
2026/05/28
[jira] [Assigned] (CXF-9218) Respect configured ProxySelector instead of hard-wiring system proxy properties
Freeman Yue Fang (Jira)
-
2026/05/28
[jira] [Commented] (CXF-9218) Respect configured ProxySelector instead of hard-wiring system proxy properties
Freeman Yue Fang (Jira)
-
2026/05/28
[jira] [Commented] (CXF-9129) Chunked attachment streaming not working when using ws-security
Freeman Yue Fang (Jira)
-
2026/05/28
[jira] [Created] (CXF-9218) Respect configured ProxySelector instead of hard-wiring system proxy properties
Matthias Pretzer (Jira)
-
2026/05/27
[jira] [Assigned] (CXF-9129) Chunked attachment streaming not working when using ws-security
Freeman Yue Fang (Jira)
-
2026/05/27
[jira] [Commented] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Andriy Redko (Jira)
-
2026/05/27
[jira] [Closed] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Markus Jung (Jira)
-
2026/05/27
[jira] [Commented] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Markus Jung (Jira)
-
2026/05/25
[jira] [Commented] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Markus Jung (Jira)
-
2026/05/25
[jira] [Comment Edited] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Andriy Redko (Jira)
-
2026/05/25
[jira] [Commented] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Andriy Redko (Jira)
-
2026/05/25
[jira] [Created] (CXF-9217) UriInfoImpl#getMatchedResourceTemplate() omits the @ApplicationPath from the returned template
Markus Jung (Jira)
-
2026/05/22
[jira] [Commented] (CXF-8966) Failure to validate null xsd:int
Peter Palaga (Jira)
-
2026/05/22
[jira] [Updated] (CXF-9213) RetryStrategy is a stateful class whose objects shouldn't be reused
Freeman Yue Fang (Jira)
-
2026/05/21
[jira] [Commented] (CXF-8913) Avoid 3rd party maven repository for OpenSAML
Claus Ibsen (Jira)
-
2026/05/21
[jira] [Resolved] (CXF-9216) Switch default OAuth2 code verifier to Digest
Colm O hEigeartaigh (Jira)
-
2026/05/21
[jira] [Created] (CXF-9216) Switch default OAuth2 code verifier to Digest
Colm O hEigeartaigh (Jira)
-
2026/05/21
[jira] [Created] (CXF-9215) Enforce PKCE by default
Colm O hEigeartaigh (Jira)
-
2026/05/20
[jira] [Resolved] (CXF-9214) WSDLs and XSDs cannot be loaded from class path on GraalVM
Colm O hEigeartaigh (Jira)