Answer in brief
CVE-2026-73179 records a Unknown severity vulnerability in Apache CXF: JPA authorization-code consume is non-atomic. The current sources do not mark it as known exploited. The current feed maps Apache Software Foundation/org.apache.cxf:cxf-rt-rs-security-oauth2 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Apache Software Foundation/org.apache.cxf:cxf-rt-rs-security-oauth2 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/org.apache.cxf:cxf-rt-rs-security-oauth2generic | >=4.2.0 <4.2.4 || >=4.0.0 <4.1.9 || >=0 <3.6.13 | 4.2.4, 4.1.9, 3.6.13 |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue.
Quoted source text, attributed separately from HOL analysis.