GHSA-pg32-686q-qh6x

Suggest an improvement
Source
https://github.com/advisories/GHSA-pg32-686q-qh6x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pg32-686q-qh6x/GHSA-pg32-686q-qh6x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pg32-686q-qh6x
Aliases
Published
2026-05-26T13:30:16Z
Modified
2026-06-29T23:26:32Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Apache CXF has an LDAP injection vulnerability
Details

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-90"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-29T23:02:03Z",
    "nvd_published_at":  "2026-05-22T13:16:22Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Maven
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap

Package

Name
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-x509-repo-ldap

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.2.1

Affected versions

4.*
4.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pg32-686q-qh6x/GHSA-pg32-686q-qh6x.json"
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap

Package

Name
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-x509-repo-ldap

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Fixed
4.1.6

Affected versions

4.*
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pg32-686q-qh6x/GHSA-pg32-686q-qh6x.json"
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap

Package

Name
org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap
View open source insights on deps.dev
Purl
pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-x509-repo-ldap

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.11

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.2.10
3.2.11
3.2.12
3.2.13
3.2.14
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.3.10
3.3.11
3.3.12
3.3.13
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.10
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.5.10
3.5.11
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.6.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pg32-686q-qh6x/GHSA-pg32-686q-qh6x.json"