CVE-2026-50629

5.3 MEDIUM
Published: June 12, 2026 Modified: June 12, 2026
View on NVD

Description

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files.Β Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://lists.apache.org/thread/xw95po30p8th58ms1no6b0f2375cql00
Source: security@apache.org
Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/06/11/6
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory

2 reference(s) from NVD

Quick Stats

CVSS v3 Score
5.3 / 10.0
EPSS (Exploit Probability)
0.2%
39th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

apache