CVE-2026-100227 | Apache CXF up to 3.6.12/4.1.8/4.2.3 JAX-RS XML Signature Interceptors data authenticity

SecurityVulns

A vulnerability, which was classified as critical, has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3. The impacted element is the function XmlSigInHandler/XmlSigInInterceptor/XmlSecInInterceptor of the component JAX-RS XML Signature Interceptors. The manipulation leads to insufficient verification of data authenticity.

This vulnerability is traded as CVE-2026-100227. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More