CVE-2026-71575
EUVD-2026-9569409.10.2026, 11:17
The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | cxf | 4.2.0 ≤ 𝑥 < 4.2.4 | CNA |
| apache | cxf | 4.0.0 ≤ 𝑥 < 4.1.9 | CNA |
| apache | cxf | 𝑥 < 3.6.13 | CNA |
Common Weakness Enumeration