CVE-2026-79650: Apache CXF: OIDC RP Open Redirect
Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL after successful authentication. The issue occurs because attacker-controlled state parameters are preserved and later used as redirect targets without validating that the final decoded URI belongs to the RP’s origin. Both directly encoded and double-encoded external URLs can trigger the issue, depending on which validation path is used. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXF OIDC relying-party componentto a version that resolves this vulnerability.Fixed in 4.2.4 - Upgrade
Upgrade
Apache CXF OIDC relying-party componentto a version that resolves this vulnerability.Fixed in 4.1.9 - Upgrade
Upgrade
Apache CXF OIDC relying-party componentto a version that resolves this vulnerability.Fixed in 3.6.13
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments using Apache CXF’s OIDC relying-party component are exposed if they run a version earlier than 4.2.4, 4.1.9, or 3.6.13.
What does an attacker need to exploit it?
An attacker needs to supply a crafted state parameter that contains an external redirect URL. Both directly encoded and double-encoded external URLs may work, depending on the validation path used.
What is the practical impact?
After a user successfully authenticates, the relying party can redirect the user to an attacker-controlled URL. This can make a malicious destination appear to be part of an otherwise legitimate authentication flow.
How can the issue be remediated?
Upgrade Apache CXF to version 4.2.4, 4.1.9, or 3.6.13, which validate that the final decoded redirect URI belongs to the relying party’s origin.