Medium severity5.3NVD Advisory· Published Jun 12, 2026· Updated Aug 7, 2026
CVE-2026-50629
CVE-2026-50629
Description
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.cxf:cxf-rt-rs-security-oauth2Maven | >= 4.2.0, < 4.2.2 | 4.2.2 |
org.apache.cxf:cxf-rt-rs-security-oauth2Maven | < 4.1.7 | 4.1.7 |
Affected products
2- Range: before 4.2.2, 4.1.7, 3.6.12
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2026/06/11/6nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-f8p7-h97q-7vx7ghsaADVISORY
- lists.apache.org/thread/xw95po30p8th58ms1no6b0f2375cql00nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-50629ghsaADVISORY
News mentions
0No linked articles in our index yet.