CVE-2026-107938
Last modified
CVE-2026-107938 is a vulnerability of currently unknown severity. In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false.
Description
In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache CXF | >= 4.2.0, < 4.2.4; >= 4.0.0, < 4.1.9; < 3.6.13 |
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-107938?
How severe is CVE-2026-107938?
How do I fix CVE-2026-107938?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107909A heap-based out-of-bounds write in the ws_read_frame functi…9.1
- CVE-2026-107910An improper authentication vulnerability in the is_authentic…8.1
- CVE-2026-107911A type confusion vulnerability in the _read_flags function (…7.5
- CVE-2026-107914Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn…7.8
- CVE-2026-107935A path traversal vulnerability was found in gvproxy, the net…9.3
- CVE-2026-107937In Apache CXF, the parser for multipart/MTOM attachment part…
- CVE-2026-10795The UpdraftPlus: WP Backup & Migration Plugin plugin for Wor…8.1
- CVE-2026-10796nvm (Node Version Manager) through 0.40.4 executes arbitrary…7.5
- CVE-2026-1080GitLab has remediated an issue in GitLab EE affecting all ve…4.3
- CVE-2026-10800A weakness has been identified in PaddlePaddle FastDeploy up…3.6
- CVE-2026-10801A security vulnerability has been detected in modelscope ms-…3.6
- CVE-2026-10802A vulnerability was detected in keystonejs keystone up to 20…4.3
Are you affected by CVE-2026-107938?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
