Published on October 9, 2026 in the oss-sec feed, advisory CVE-2026-97468 is rated important in severity. It affects Apache CXF from 4.2.0 before 4.2.4, from 4.0.0 before 4.1.9, and versions before 3.6.13. According to the description, STSTokenValidator and the Security Token Service (STS) cached validated security tokens using a 32-bit non-cryptographic hash (Java Arrays.hashCode/hashCode()). A cache hit was treated as proof that the presented token had already been validated. An attacker could therefore create a token with a hash collision and bypass authentication. The text available in Radar is truncated, so further details, such as exploitation conditions and alternative mitigations, should be checked in the original advisory. For organizations using Apache CXF, the main action is to update to a fixed version. Rota Nacional does not patch third-party libraries. If your team uses AI to study the advisory, do not paste tokens, session identifiers, keys, or internal configuration into prompts. The platform's personal data barrier detects CPF, CNPJ, e-mail, phone numbers and person names, but it does not replace manually removing credentials. To verify, compare your installed version with the affected ranges in the original advisory and the project's release notes.
Cyber ·
CVE-2026-97468: Apache CXF allows authentication bypass via weak cache keys for STS tokens
Security advisory on Apache CXF: validated STS tokens were cached using a 32-bit non-cryptographic hash, which may allow an attacker to craft a colliding token. Fixed versions are listed.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.