org.apache.cxf:cxf-rt-rs-security-oauth2

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.apache.cxf:cxf-rt-rs-security-oauth2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Time-of-check Time-of-use (TOCTOU) Race Condition

[,4.1.7)[4.2.0,4.2.2)
  • M
HTTP Response Splitting

[,4.1.7)[4.2.0,4.2.2)
  • H
Authentication Bypass by Alternate Name

[,4.1.7)[4.2.0,4.2.2)
  • M
Missing Authentication for Critical Function

[,4.1.7)[4.2.0,4.2.2)
  • M
CRLF Injection

[,4.1.7)[4.2.0,4.2.2)
  • H
Improperly Implemented Security Check for Standard

[,4.1.7)[4.2.0,4.2.2)
  • H
Denial of Service (DoS)

[,3.3.10)[3.4.0,3.4.3)
  • H
Timing Attack

[,3.0.13)[3.1.0,3.1.10)

Package versions

160 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
4.2.114 May, 2026
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.2.010 Feb, 2026
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.614 May, 2026
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.510 Feb, 2026
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.411 Nov, 2025
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.330 Jul, 2025
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.216 May, 2025
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.13 Mar, 2025
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.1.09 Dec, 2024
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L
4.0.1110 Feb, 2026
  • 1
    C
  • 2
    H
  • 3
    M
  • 0
    L