CVE-2026-71575: Apache Software Foundation Apache Cxf
EPSS: 0.2% chance of exploitation in the next 30 days.
The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Affected products
- Apache Software Foundation Apache Cxf: from 4.2.0, before 4.2.4 (fixed in 4.2.4); from 4.0.0, before 4.1.9 (fixed in 4.1.9); before 3.6.13 (fixed in 3.6.13)
Published 2026-10-09. Last modified 2026-10-09.