In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Cxf
APPApache< 3.6.124.0.0 – 4.1.8 (excl.)4.2.0 – 4.2.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-65583CRITICAL9.1PL ✓same product
Apache CXF: pominięcie walidacji tokenów OIDC umożliwia authentication bypass
CVE-2026-66909CRITICAL9.8PL ✓same product
Apache CXF: RCE przez niebezpieczną deserializację JMS ObjectMessage
CVE-2026-61466CRITICAL9.1PL ✓same product
Apache CXF: brak walidacji scope w rejestracji klienta OAuth2
CVE-2026-63687CRITICAL9.1PL ✓same product
Apache CXF: podmiana parametrów PKCE i OIDC przez JWT w JwtRequestCodeFilter
CVE-2026-50627CRITICAL9.1PL ✓same product
Apache CXF: brak walidacji pola 'aud' w tokenach JWT — Token Confusion