Severity: low 

Affected versions:

- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.2
- Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 4.1.7

Description:

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. 
When constructing the WWW-Authenticate response header, the 'realm' parameter 
is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) 
characters. If an attacker can control the realm value, they can inject 
arbitrary HTTP headers or split the HTTP response entirely. Users are 
recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

Credit:

Guanping Zhang reported this vulnerability. (finder)

References:

https://cxf.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-50630

Reply via email to