Published on October 9, 2026 in the oss-sec feed by Colm O hEigeartaigh, advisory CVE-2026-107938 describes a high-severity flaw in the Netty-based HTTP client transport of Apache CXF, in the cxf-rt-transports-http-netty-client module. The client did not verify that the accessed host matched the name in the server TLS certificate. The flaw affects HTTP/1.1 and HTTP/2, even when the disableCNCheck option keeps its default value of false. Affected versions: 4.2.0 before 4.2.4; 4.0.0 before 4.1.9; and versions before 3.6.13. Those who use these libraries should update to the fixed version of their release line and confirm, in the build, the version actually resolved. To verify, consult the original advisory in the oss-sec feed and the CVE record, without relying only on this summary.
Cyber ·
CVE-2026-107938: Apache CXF Netty HTTP client does not verify TLS certificate host name
Apache CXF advisory on the Netty-based HTTP client, which does not check that the host name matches the server TLS certificate, with affected versions and fixed release lines.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.