<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:20:51 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-50627 — Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-50627</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache CXF, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Web Server 5&lt;/p&gt;
&lt;p&gt;The JwtAccessTokenValidator class in Apache CXF fails to validate the &amp;#39;aud&amp;#39; (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache CXF, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Web Server 5&lt;/p&gt;
&lt;p&gt;The JwtAccessTokenValidator class in Apache CXF fails to validate the &amp;#39;aud&amp;#39; (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-50627</guid>
    </item>
  </channel>
</rss>
