Get real-time updates on Telegram
Verified
CVE-2026-97468: Apache CXF 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13
Affected technology
Apache CXF · 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13
Apache Software Foundation
Component: Not specified by the source
What an attacker can do
An attacker could craft a token (for example a UsernameToken or a self-signed SAML Assertion) whose hash collides with a cached entry.
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-97468.html