Description
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Severity (CVSS)
| Base score | 8.1 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Provided by | CISA-ADP |
Weaknesses
- CWE-20 — CWE-20 Improper Input Validation
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache CXF | 4.2.0 to <4.2.3; 4.0.0 to <4.1.8; 0 to <3.6.12 |
References
Generated from the official CVE List on 07 Aug 2026 07:02 UTC.