CVE-2026-97468

CVE-2026-97468 published: Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens under a non-cryptographic 32-bit hash of the token (Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the presented token had already been...

View full NVD advisory → ← Back to CVE watch