CVE-2026-50634: Apache Cxf

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type` or protected HTTP-header metadata came from a verified signature entry, and may steer downstream JAX-RS entity parsing or signed-header consistency checks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.

Affected products

  • Apache Cxf: before 4.1.7 (fixed in 4.1.7); from 4.2.0, before 4.2.2 (fixed in 4.2.2)

Published 2026-06-12. Last modified 2026-08-07.