Severity: important 

Affected versions:

- Apache CXF 4.2.0 before 4.2.4
- Apache CXF 4.0.0 before 4.1.9
- Apache CXF before 3.6.13

Description:

In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a 
trusted certificate before deciding to send it to the STS. That result was 
stored in one object shared by all requests, so one request could read 
another's result. A remote, unauthenticated attacker could send a forged 
assertion signed with an untrusted certificate while legitimate requests were 
being processed, and it could be accepted as trusted without ever reaching the 
STS. Only services that use STSTokenValidator to validate SAML tokens without 
alwaysValidateToSts set are affected. 
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which 
fix this issue.

Credit:

MopMonk-AI (finder)

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-97791

Reply via email to