What is CVE-2026-57817?
CVE-2026-57817: The OpenID Connect Core 1.0 spec requires RP to validate 'c_hash' in Hybrid Flow. When Apache CXF RP integrates with a non-compliant IdP omitting 'c_hash', it becomes vulnerable to authorization code interception. Mitigation involves ensuring the IdP provides 'c_hash' or reviewing Apache CXF RP configuration.
Azərbaycanca: CVE-2026-57817: OpenID Connect Core 1.0 spesifikasiyasına əsasən, Hybrid Flow rejimində RP (Relying Party) 'c_hash' parametrini mütləq yoxlamalıdır. Apache CXF RP-si 'c_hash' göndərməyən uyğunsuz IdP ilə inteqrasiya edildikdə, icazə kodunun ələ keçirilməsi riski yaranır. Təsirə məruz qalmamaq üçün IdP-nin 'c_hash' göndərdiyinə əmin olun və ya Apache CXF konfiqurasiyasını yoxlayın.
Related CVEs
link basis: shared vendor: Apache
FAQ2
In which component was CVE-2026-57817 discovered?
CVE-2026-57817 was discovered in the Apache CXF RP (Relying Party) component when interacting with an IdP not compliant with the OpenID Connect Core 1.0 specification.
What is the root cause of this vulnerability?
The vulnerability arises from the failure to validate the 'c_hash' parameter in Hybrid Flow mode, creating a risk of authorization code interception.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.