Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-50631

2 месяца назад

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-83r6-96m8-r52p

2 месяца назад

Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh token can be replayed concurrently by multiple attackers or threads. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

CVSS3: 7.4
0%
Низкий
2 месяца назад
github логотип
GHSA-83r6-96m8-r52p

Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing

CVSS3: 7.4
0%
Низкий
2 месяца назад

Уязвимостей на страницу