Insufficient verification of data authenticity in Apache CXF - CVE-2026-50634
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to influence downstream request parsing and signed-header consistency checks.
The vulnerability exists due to improper authentication in JwsJsonContainerRequestFilter when processing WS JSON requests with multiple signature entries. A remote user can supply a request in which metadata is taken from an unvalidated first signature entry to influence downstream request parsing and signed-header consistency checks.
The issue affects assumptions that accepted Content-Type or protected HTTP-header metadata came from the accepted signature entry.