Apache disclosed CVE-2026-65583, a low-severity flaw in the Apache CXF OIDC relying-party token validation logic that can cause self-issued ID tokens to be accepted without required claim checks. Missing validation may skip verification of fields such as issuer, subject, audience, time-based claims, and sub_jwk binding, creating a path for authentication bypass with crafted tokens in deployments that accept self-issued ID tokens.
The issue affects the Apache CXF module org.apache.cxf:cxf-rt-rs-security-sso-oidc in versions 4.2.0 before 4.2.3, 4.0.0 before 4.1.8, and the 3.6.x line before 3.6.12. Apache said self-issued ID tokens are not accepted by default in the validator, but advised users to upgrade to 4.2.3, 4.1.8, or 3.6.12 to remediate the vulnerability. Guanping Zhang was credited with reporting the issue.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-06, Apache disclosed CVE-2026-65583 affecting org.apache.cxf:cxf-rt-rs-security-sso-oidc and said the issue was fixed in versions 4.2.3, 4.1.8, and 3.6.12. Apache also advised users to upgrade, noting that self-issued ID tokens are not accepted by default in the validator.
Apache credited Guanping Zhang with reporting CVE-2026-65583, a low-severity flaw in Apache CXF's OIDC relying-party token validation that could allow crafted self-issued ID tokens to bypass required claim checks. The content does not anchor a date for when the report was made.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceopenwall.com
Open sourcelists.apache.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.