Vulnerability Description
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.6.12 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/pj63c3pf7kkp1xhr53do704fwj3t3htnMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/06/19
FAQ
What is CVE-2026-57817?
CVE-2026-57817 is a vulnerability with a CVSS score of 8.1 (HIGH). The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconf...
How severe is CVE-2026-57817?
CVE-2026-57817 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57817?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf.