CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-100227: Apache CXF 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13

Affected technology

Apache CXF · 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13
Apache Software Foundation

Component: Not specified by the source

What an attacker can do

An attacker with any document signed by a trusted key could wrap it in unsigned content, which the application would then treat as signed.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-100227.html