THREATOPS
THREAT OPSThreat News › CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters

CVE-2026-63687: Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters

medoss_secPublished 2026-08-06

<p>Posted by Colm O hEigeartaigh on Aug 06</p>Severity: low <br /> <br /> Affected versions:<br /> <br /> - Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.3<br /> - Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.0.0 before 4.1.8<br /> - Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 3.6.12<br /> <br /> Description:<br /> <br /> Apache CXF&apos;s JwtRe

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/476