CVE-2026-73179

CVE-2026-73179 published: Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange r...

View full NVD advisory → ← Back to CVE watch