Apache CXF vulnerability CVE-2026-50645 and other CVEs requiring CXF 4.1.7 for resolution detected in JBoss EAP 8.1
Issue
- A security scanner identifies a vulnerability in the CXF core JAR located at
$EAP_HOME/modules/system/layers/base/org/apache/cxf/main/cxf-core-4.0.10.redhat-00001.jar. - The scan flags CVE-2026-50645 as a high impact along with other CVEs all addressed in CXF 4.1.7 or later.
Environment
- Red Hat JBoss Enterprise Application Platform (EAP) 8.1
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.