CVE-2026-97791

CVE-2026-97791 published: In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests, so one request could read another's result. A remote, una...

View full NVD advisory → ← Back to CVE watch