GHSA-33j8-j763-4fv5
MODERATECVE-2026-50634A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption
- Affected
- >= 4.2.0, < 4.2.2
- Fixed in
- 4.2.2
- Weakness
- CWE-347
- Published
- 2026-06-12
- Source
- github