CVE-2017-3156: Apache Cxf

High severity, CVSS 7.5. EPSS: 6.3% chance of exploitation in the next 30 days.

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

Affected products

  • Apache Cxf: up to and including 3.0.12; version 3.1.0 only; version 3.1.1 only; version 3.1.2 only; version 3.1.3 only; version 3.1.4 only; …

Published 2017-08-10. Last modified 2026-06-17.