CVE-2026-71575 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Max Age Authentication-Freshness Check OidcClientCodeRequestFilter incorrect operator
A vulnerability identified as critical has been detected in Apache CXF up to 3.6.12/4.1.8/4.2.3. This issue affects the function OidcClientCodeRequestFilter of the component Max Age Authentication-Freshness Check. This manipulation causes use of incorrect operator.
This vulnerability is tracked as CVE-2026-71575. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More