Vulnerability Description
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 4.1.7 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/xw95po30p8th58ms1no6b0f2375cql00Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/11/6Mailing ListThird Party Advisory
FAQ
What is CVE-2026-50629?
CVE-2026-50629 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary...
How severe is CVE-2026-50629?
CVE-2026-50629 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50629?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf.