{"id":"ECHO-0e19-deb4-9c3d","upstream":["CVE-2026-50645","GHSA-ghvc-7hp8-2g2v"],"severity":[],"modified":"2026-09-30T11:25:20.758Z","affected":[{"package":{"ecosystem":"Echo:Maven","name":"org.apache.cxf:cxf-core","purl":"pkg:maven/org.apache.cxf/cxf-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.12"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-50645"},{"type":"WEB","url":"https://github.com/advisories/GHSA-ghvc-7hp8-2g2v"}]}