CVE-2026-107938 | Apache CXF up to 3.6.12/4.1.8/4.2.3 cxf-rt-transports-http-netty-client certificate validation
A vulnerability described as problematic has been identified in Apache CXF up to 3.6.12/4.1.8/4.2.3. This issue affects some unknown processing of the component cxf-rt-transports-http-netty-client. Such manipulation leads to improper certificate validation.
This vulnerability is documented as CVE-2026-107938. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More