Description
Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL after successful authentication. The issue occurs because attacker-controlled state parameters are preserved and later used as redirect targets without validating that the final decoded URI belongs to the RP’s origin. Both directly encoded and double-encoded external URLs can trigger the issue, depending on which validation path is used. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Phishing via open redirect after authentication
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates in Apache CXF’s OIDC relying‑party component, where attacker‑controlled state parameters are later used to construct a redirect target without validating the final decoded URI. After a successful authentication, the application can redirect a user to an arbitrary external URL, potentially leading to phishing or credential theft. The flaw is a classic open‑redirect issue, not a code execution vector, but it enables an attacker to influence user navigation and trust context.

Affected Systems

The affected product is Apache CXF, specifically the OIDC relying‑party component. Versions preceding 4.2.4, 4.1.9, and 3.6.13 contain the flaw. Users running these releases are at risk until they upgrade.

Risk and Exploitability

No EPSS data is available and the vulnerability is not listed in CISA KEV, indicating limited public exploitation evidence. However, the CVE description warns that both directly and double‑encoded URLs can trigger the redirect, suggesting that the attack vector is straightforward once the attacker can supply a state parameter. The issue is considered high impact because it can facilitate phishing attacks post-authentication, and the fixed releases provide a straightforward remediation path.

Generated by OpenCVE AI on October 9, 2026 at 11:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache CXF to version 4.2.4, 4.1.9, or 3.6.13, which contain the fix for the open‑redirect issue
  • If an immediate upgrade is not possible, implement server‑side validation to ensure that any redirect URI resolved from the state parameter originates from the RP’s own domain
  • Disable or restrict the OIDC RP redirect mechanism in configuration until a validated patch is deployed

Generated by OpenCVE AI on October 9, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache cxf
Vendors & Products Apache
Apache cxf

Fri, 09 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL after successful authentication. The issue occurs because attacker-controlled state parameters are preserved and later used as redirect targets without validating that the final decoded URI belongs to the RP’s origin. Both directly encoded and double-encoded external URLs can trigger the issue, depending on which validation path is used. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Title Apache CXF: OIDC RP Open Redirect
Weaknesses CWE-601
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-09T11:08:00.240Z

Reserved: 2026-08-25T10:36:59.090Z

Link: CVE-2026-79650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T11:17:03.043

Modified: 2026-10-09T11:17:03.043

Link: CVE-2026-79650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')