Apache CXF disclosed CVE-2026-57818, a low-severity flaw in the OAuth2 component org.apache.cxf:cxf-rt-rs-security-oauth2 that can let a single authorization code be redeemed multiple times. The issue stems from a time-of-check/time-of-use race condition in JCacheCodeDataProvider, allowing concurrent requests to obtain multiple distinct valid access tokens from one OAuth2 authorization code.
The vulnerability affects Apache CXF 4.2.0 before 4.2.3, 4.0.0 before 4.1.8, and 3.6.x before 3.6.12. Apache advised users to upgrade to 4.2.3, 4.1.8, or 3.6.12 to remediate the issue, and credited Guanping Zhang with reporting the bug.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Colm O hEigeartaigh announced CVE-2026-57818 on the oss-sec mailing list, describing an OAuth2 Authorization Code Replay via TOCTOU flaw in Apache CXF's org.apache.cxf:cxf-rt-rs-security-oauth2 component. The disclosure credited Guanping Zhang with reporting the vulnerability.
Apache CXF fixed a low-severity OAuth2 race condition in JCacheCodeDataProvider that could let a single authorization code be redeemed multiple times to obtain multiple valid access tokens. The issue affects versions 4.2.0 before 4.2.3, 4.0.0 before 4.1.8, and 3.6.x before 3.6.12, and users were advised to upgrade.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.