Vulnerability Description
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.6.12 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/drcq4chmt0btx86f17o47j17r378hzpwMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/06/22
FAQ
What is CVE-2026-63687?
CVE-2026-63687 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-...
How severe is CVE-2026-63687?
CVE-2026-63687 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-63687?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Cxf.