CVE-2026-57818 PUBLISHED

Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProvider

Assigner: apache
Reserved: 25.06.2026 Published: 06.08.2026 Updated: 06.08.2026

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting in the issuance of multiple distinct, valid access tokens. Users are recommended to upgrade to versions 4.2.3, 4.1.8 or 3.6.12, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache CXF
Versions Default: unaffected
  • affected from 4.2.0 to 4.2.3 (excl.)
  • affected from 4.0.0 to 4.1.8 (excl.)
  • affected from 0 to 3.6.12 (excl.)

Credits

  • Guanping Zhang reported this vulnerability finder

References

Problem Types

  • CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition CWE