Improper Output Neutralization for Logs in Apache CXF - CVE-2026-50629
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary content into log files.
The vulnerability exists due to improper neutralization of special elements used in a log entry in the OAuth2 server logging of the clientId parameter when handling incoming HTTP requests. A remote attacker can supply a crafted client identifier containing control characters to inject arbitrary content into log files.
Injected content may include fake log entries.