Junglewise Threat Intelligence

CVE-2026-50634: Apache CXF signature verification bypass in JwsJsonContainerRequestFilter

CVE-2026-50634 · Severity: medium · CVSS 6.5 · Published 2026-06-12

Technologies: Apache Software Foundation CXF. Vendors: Apache, Apache Software Foundation.

Executive brief

Apache CXF is a web services framework used to build SOAP and REST web services. A vulnerability in its JSON Web Signature filter allows attackers to bypass signature validation on HTTP metadata (such as Content-Type headers) by exploiting an unvalidated first signature entry. This could allow an attacker to inject malicious metadata that causes the application to process requests in unintended ways, potentially leading to data exposure or integrity violations.

Technical details

The vulnerability is an improper cryptographic signature verification flaw (CWE-347) in the JwsJsonContainerRequestFilter component of Apache CXF. The filter processes JSON Web Signature (JWS) formatted requests but fails to properly validate all signature entries, trusting metadata from an unvalidated first signature entry. An attacker can send a network-based JWS request with multiple signature entries, causing the filter to accept metadata (Content-Type, protected headers) that was not actually signed by a trusted key. This can lead to bypass of signature validation assumptions, potentially steering downstream JAX-RS entity parsing or causing inconsistencies in signed-header validation logic. No authentication or user interaction is required. Patches are available in Apache CXF versions 4.2.2 (for 4.2.0+) and 4.1.7 (for earlier branches).

Affected products

  • Apache CXF cxf-rt-rs-security-jose-jaxrs 4.2.0 to 4.2.1, all versions before 4.1.7

Timeline

  • 2026-06-11: disclosed: CVE-2026-50634 disclosed on oss-security mailing list
  • 2026-06-12: patched: Fixes available in Apache CXF 4.2.2 and 4.1.7
  • 2026-06-12: advisory: GitHub Advisory GHSA-33j8-j763-4fv5 published

References

Related threats