CVE-2026-73179: Apache CXF: JPA authorization-code consume is non-atomic Severity: low Affected versions: - Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.2.0 before 4.2.4 - Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) 4.0.0 before 4.1.9 - Apache CXF (org.apache.cxf:cxf-rt-rs-security-oauth2) before 3.6.13 Description: Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue. Credit: Guanping Zhang reported this vulnerability (finder) References: https://cxf.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-73179