CVE-2026-63687
critical · 9.1Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
9.1
CVSS
0.3%
EPSS (exploit prob.)
19th
EPSS percentile
2026-08-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-345
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | cxf | < 3.6.12 |
| apache | cxf | >= 4.0.0, < 4.1.8 |
| apache | cxf | >= 4.2.0, < 4.2.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-63687