Apache CXF vulnerability CVE-2026-50645 detected in JBoss EAP 8.1
Issue
We upgraded our environment to JBoss EAP 8.1 Update 6.0 specifically to address Apache CXF-related vulnerabilities reported by our security scanner. Following the upgrade, the scanner still identifies a vulnerability in the CXF core JAR located at /apps/jboss-eap-8.1/modules/system/layers/base/org/apache/cxf/main/cxf-core-4.0.10.redhat-00001.jar.
The scan reports Apache CXF version 4.0.10 and flags CVE-2026-50645, noting that severity is High.
Environment
- Red Hat JBoss Enterprise Application Platform (EAP) 8.1
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.