{
  "threat_severity" : "Important",
  "public_date" : "2026-05-22T12:16:47Z",
  "bugzilla" : {
    "description" : "apache-cxf: org.apache.cxf.services.xkms/cxf-services-xkms-x509-repo-ldap: Apache CXF: Information Disclosure via LDAP Injection",
    "id" : "2480728",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2480728"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-90",
  "details" : [ "An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository. \nUsers are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.", "A flaw was found in Apache CXF. A remote attacker could exploit an LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server. This vulnerability allows the attacker to retrieve arbitrary certificates from the repository, leading to information disclosure." ],
  "statement" : "This is an Important information disclosure flaw in Apache CXF's XKMS server, allowing a remote attacker to retrieve arbitrary certificates via an LDAP injection vulnerability in the LDAP Certificate repository. This impact is considered Important due to the potential for unauthorized access to sensitive cryptographic material without requiring prior authentication, affecting the confidentiality of services utilizing the cxf-services-xkms-x509-repo-ldap component in Red Hat products.",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37390",
    "cpe" : "cpe:/a:redhat:apache_camel_spring_boot:4.18",
    "package" : "cxf-services-xkms-x509-repo-ldap"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Fix deferred",
    "package_name" : "cxf-services-xkms-x509-repo-ldap",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "cxf-services-xkms-x509-repo-ldap",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-44930\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-44930\nhttps://lists.apache.org/thread/c1zqxppo1m5z3kbdhjn5p991zk09ynkh" ],
  "name" : "CVE-2026-44930",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}