CVE-2026-100227 Apache CXF JAX-RS XML 签名校验不当漏洞
影响攻击者可绕过签名校验注入未签名内容
Apache CXF 的 JAX-RS XML Security 模块在验证 XML 数字签名时存在缺陷,未能确保传入应用的 XML 内容完全被签名覆盖。攻击者可利用任意由受信任密钥签名的文档,在其外层包裹未签名内容,使应用误将未签名部分视为已签名。
影响范围
受影响组件为 Apache CXF 的 JAX-RS XML Security 模块(XmlSigInHandler、XmlSigInInterceptor、XmlSecInInterceptor)。官方建议升级至 4.2.4、4.1.9 或 3.6.13,此前版本均受影响。
漏洞详情
该漏洞属于密码签名验证不当(XML 签名包装,XML Signature Wrapping)。成因是签名拦截器仅验证了签名本身有效,却未校验签名所覆盖的 XML 元素是否就是应用实际处理的完整文档。攻击者只需持有一份由受信任密钥签名的合法文档,即可将恶意未签名内容包裹在其周围,应用会错误地将其当作已签名数据接受。
利用条件与风险
利用前提是攻击者能获取任意一份由受信任密钥签名的 XML 文档,且目标应用使用上述拦截器处理签名消息。实战中可导致身份伪造、数据篡改或绕过安全校验,风险较高。
修复建议
官方修复方案为升级至 4.2.4、4.1.9 或 3.6.13 版本。临时缓解措施暂无公开信息,建议尽快升级并审查依赖 XML 签名的业务流程。
Improper Verification of Cryptographic Signature vulnerability in Apache CXF’s JAX-RS XML Security module. The JAX-RS XML Signature interceptors (XmlSigInHandler, XmlSigInInterceptor and the streaming XmlSecInInterceptor) did not ensure that the XML passed to the application was covered by the signature. An attacker with any document signed by a trusted key could wrap it in unsigned content, which the application would then treat as signed.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.