CVE-2026-73179: Apache CXF: JPA authorization-code consume is non-atomic
Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READCOMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.2.4 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 3.6.13
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using Apache CXF's JPA OAuth2 authorization-code grant provider with a shared relational database under READ_COMMITTED isolation are exposed. The issue affects the provider's non-atomic find-then-delete handling of authorization codes.
What does an attacker need to exploit this issue?
An attacker needs a valid authorization code and must submit concurrent token exchange requests. The requests race the code consumption operation, allowing multiple valid access tokens to be issued from one code.
How can this be remediated?
Upgrade Apache CXF to version 4.2.4, 4.1.9, or 3.6.13. These versions fix the non-atomic authorization-code consumption issue.