{"api_version":"1","generated_at":"2026-10-11T00:30:07+00:00","cve":"CVE-2026-107938","urls":{"html":"https://cve.report/CVE-2026-107938","api":"https://cve.report/api/cve/CVE-2026-107938.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107938","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107938"},"summary":{"title":"Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.","description":"In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials. \nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-10-09 11:17:02","updated_at":"2026-10-09 16:33:39"},"problem_types":[],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/13","name":"http://www.openwall.com/lists/oss-security/2026/10/09/13","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread.html/ljsjsq1foyjy1v5o22oncw80twx7k2tc","name":"https://lists.apache.org/thread.html/ljsjsq1foyjy1v5o22oncw80twx7k2tc","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107938","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107938","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache CXF","version":"affected 4.2.0 4.2.4 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache CXF","version":"affected 4.0.0 4.1.9 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache CXF","version":"affected 3.6.13 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"This issue was found using Claude agents to study the security of open-source projects","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"107938","cve":"CVE-2026-107938","epss":"0.001150000","percentile":"0.014680000","score_date":"2026-10-10","updated_at":"2026-10-11 00:07:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-10-09T11:07:53.753Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/13"}],"title":"CVE Program Container"}],"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.cxf:cxf-rt-transports-http-netty-client","packageURL":"pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client","product":"Apache CXF","vendor":"Apache Software Foundation","versions":[{"lessThan":"4.2.4","status":"affected","version":"4.2.0","versionType":"semver"},{"lessThan":"4.1.9","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.13","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"This issue was found using Claude agents to study the security of open-source projects"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"In Apache CXF, the Netty-based HTTP client transport (<code>cxf-rt-transports-http-netty-client</code>) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when <code>disableCNCheck</code> was left at its default value of <code>false</code>. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials.&nbsp;<br>Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue."}],"value":"In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials. \nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-10-09T10:20:11.627Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread.html/ljsjsq1foyjy1v5o22oncw80twx7k2tc"}],"source":{"discovery":"UNKNOWN"},"title":"Apache CXF: The Netty HTTP client transport does not perform TLS hostname verification.","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-107938","datePublished":"2026-10-09T10:20:11.627Z","dateReserved":"2026-10-09T09:19:43.226Z","dateUpdated":"2026-10-09T11:07:53.753Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-09 11:17:02","lastModifiedDate":"2026-10-09 16:33:39","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107938","Ordinal":"1","Title":"Apache CXF: The Netty HTTP client transport does not perform TLS","CVE":"CVE-2026-107938","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107938","Ordinal":"1","NoteData":"In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials. \nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","Type":"Description","Title":"Apache CXF: The Netty HTTP client transport does not perform TLS"}]}}}