CVE-2026-107938 Apache CXF Netty 客户端 TLS 主机名校验缺失漏洞
影响中间人可冒充目标服务,读取或篡改通信内容及凭据
Apache CXF 基于 Netty 的 HTTP 客户端传输组件(cxf-rt-transports-http-netty-client)在建立 TLS 连接时未校验服务器证书中的主机名是否与所调用主机一致。该问题同时影响 HTTP/1.1 与 HTTP/2,且即使 disableCNCheck 保持默认值 false 也依然存在。证书链会依据配置的信任库进行验证,但端点身份未被确认。
影响范围
受影响组件为 Apache CXF 的 cxf-rt-transports-http-netty-client 模块,官方修复版本为 4.2.4、4.1.9 和 3.6.13,具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于 TLS 服务器身份校验缺失(主机名校验绕过)。客户端虽然验证了服务器证书链是否由受信任 CA 签发,却没有检查证书中的主机名(CN/SAN)是否匹配实际访问的主机。网络攻击者若能拦截流量,可出示任意被客户端信任的证书(例如其控制的域名所签发的公网证书)来冒充目标服务,进而读取或修改包括凭据在内的通信内容。
利用条件与风险
利用前提是攻击者具备中间人位置(如控制网络路径或 DNS),且客户端使用该 Netty 传输组件发起 TLS 连接。实战中可导致敏感凭据泄露与消息篡改,风险较高。
修复建议
官方建议升级至 4.2.4、4.1.9 或 3.6.13 版本以修复该问题。临时缓解措施暂无公开信息。
In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials.
Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.