Junglewise Threat Intelligence

CVE-2026-50631: Apache CXF race condition in AbstractOAuthDataProvider

CVE-2026-50631 · Severity: high · CVSS 7.4 · Published 2026-06-12

Technologies: Apache Software Foundation CXF. Vendors: Apache Software Foundation, Apache.

Executive brief

Apache CXF is a widely-used framework for building web services and OAuth2-protected APIs. A timing flaw in its token handling allows attackers who obtain a single refresh token to generate multiple valid access tokens by making concurrent requests. This could enable account takeover or unauthorized data access if a refresh token is leaked or compromised. The issue only occurs when token recycling is disabled in the configuration.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in AbstractOAuthDataProvider's refresh token validation logic. When recycleRefreshTokens is set to false, the component checks token validity before consuming it, but concurrent requests can bypass this check and each generates a new access token from the same refresh token. An attacker with network access (no authentication required) can exploit this by issuing multiple simultaneous HTTP requests with an intercepted refresh token, bypassing the intended single-use semantics. This allows generation of multiple valid access tokens for the same identity, leading to unauthorized API access and potential data exposure. The fix in versions 4.2.2 and 4.1.7 implements proper locking to serialize token consumption.

Affected products

  • Apache CXF 4.2.0 before 4.2.2, and before 4.1.7

Timeline

  • 2026-06-12: disclosed: Published to GitHub Advisory Database and NVD
  • 2026-06-12: patched: Patches released: CXF 4.2.2 and 4.1.7

References

Related threats