HTTP response splitting in Apache CXF - CVE-2026-50630
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary HTTP headers or split the HTTP response entirely.
The vulnerability exists due to crlf injection in the OAuth2 AuthorizationUtils class when constructing the WWW-Authenticate response header with an attacker-controlled realm value. A remote attacker can supply a crafted realm value to inject arbitrary HTTP headers or split the HTTP response entirely.