CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-97468: Apache CXF 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13

Affected technology

Apache CXF · 4.2.0 to before 4.2.4, 4.0.0 to before 4.1.9, 0 to before 3.6.13
Apache Software Foundation

Component: Not specified by the source

What an attacker can do

An attacker could craft a token (for example a UsernameToken or a self-signed SAML Assertion) whose hash collides with a cached entry.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-97468.html