Home

Description

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

PUBLISHED Reserved 2026-06-05 | Published 2026-06-12 | Updated 2026-06-15 | Assigner apache

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

4.2.0 (semver) before 4.2.2
affected

Any version before 4.1.7
affected

Credits

Guanping Zhang reported this vulnerability finder

References

www.openwall.com/lists/oss-security/2026/06/11/5

lists.apache.org/thread/vb3ho8lf228gh90m1fpnohf2008xrdxk vendor-advisory

cve.org (CVE-2026-50628)

nvd.nist.gov (CVE-2026-50628)

Download JSON