On 9 October 2026, the oss-sec list published an advisory on CVE-2026-100227, rated moderate severity. The issue is in the JAX-RS XML Security module of Apache CXF: the JAX-RS XML signature interceptors (XmlSigInHandler, XmlSigInInterceptor and the streaming XmlSecInInterceptor) did not guarantee that the XML passed to the application was covered by the verified signature, which describes an XML Signature wrapping flaw. Affected versions are Apache CXF 4.2.0 before 4.2.4, Apache CXF 4.0.0 before 4.1.9, and Apache CXF before 3.6.13. The available text is an automatic translation and is truncated, so full technical details, such as exploitation conditions and impact analysis, should be checked in the original source, found through the oss-sec list name and the CVE identifier. To check whether your organization is affected, list the Apache CXF dependencies in JAX-RS services that validate XML signatures and compare the version with the ranges above. Rota Nacional does not patch this library or replace signature validation in your service, and this item does not describe any platform feature applied to the problem. If the team uses AI to study the advisory or review code, avoid pasting real XML messages, tokens or certificates; the platform detects and applies the personal data policy before the model, but technical secrets should be removed by the user.
Cyber ·
CVE-2026-100227: XML Signature wrapping flaw in the Apache CXF JAX-RS module
Moderate-severity advisory on Apache CXF XML signature interceptors that did not guarantee the XML delivered to the application was covered by the verified signature. Fixed versions are listed.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.