AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63687

CRITICAL · CVSS 9.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache CXF's JwtRequestCodeFilter is vulnerable as it improperly handles claims from signed JWTs, allowing attackers with access to a valid client_secret to manipulate critical parameters like code_challenge and nonce. This flaw compromises the integrity of the PKCE mechanism and exposes systems to potential replay attacks in OpenID Connect implementations. Organizations using affected versions of Apache CXF should prioritize upgrading to versions 4.2.3, 4.1.8, or 3.6.12 to mitigate this critical risk.

CVE
CVE-2026-63687
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%
Apache

Original NVD Description

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)