Medium severity5.3NVD Advisory· Published Jun 12, 2026· Updated Jun 12, 2026
CVE-2026-50629
CVE-2026-50629
Description
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/11/6nvdMailing ListThird Party Advisory
- lists.apache.org/thread/xw95po30p8th58ms1no6b0f2375cql00nvdVendor Advisory
News mentions
0No linked articles in our index yet.