The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
InfoVulnerability
CVE-2026-100227: Improper Verification of Cryptographic Signature vulnerability in Apache CXF's JAX-RS XML Security module. The JAX-RS…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-100227
- Published
- Record updated
Summary
Apache CXF's JAX-RS XML Security module, specifically the XmlSigInHandler, XmlSigInInterceptor and streaming XmlSecInInterceptor, does not ensure that the XML passed to the application is covered by the signature. An attacker holding any document signed by a trusted key can wrap it in unsigned content, which the application then treats as signed.
Mitigation
Users are recommended to upgrade to versions 4.2.4, 4.1.9 or 3.6.13, which fix this issue.