CVE-2026-71575 PUBLISHED

Apache CXF: Inoperative max_age authentication-freshness check in OidcClientCodeRequestFilter

Assigner: apache
Reserved: 07.08.2026 Published: 09.10.2026 Updated: 09.10.2026

The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache CXF
Versions Default: unaffected
  • affected from 4.2.0 to 4.2.4 (excl.)
  • affected from 4.0.0 to 4.1.9 (excl.)
  • affected from 0 to 3.6.13 (excl.)

Credits

  • Guanping Zhang reported this vulnerability finder

References

Problem Types

  • CWE-613 Insufficient Session Expiration CWE