CVE-2026-71575

EUVD-2026-95694
The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
apacheCNA
UNKNOWN
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.3%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
apachecxf
4.2.0 ≤
𝑥
< 4.2.4
CNA
apachecxf
4.0.0 ≤
𝑥
< 4.1.9
CNA
apachecxf
𝑥
< 3.6.13
CNA