Apache Software Foundation Apache Wss4J vulnerabilities
7 known vulnerabilities affecting apache_software_foundation/apache_wss4j.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-88920P2CRITICALCVSS 9.8≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-88920 [CRITICAL] CWE-287 CVE-2026-88920: An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
nvd
CVE-2026-89238P3CRITICALCVSS 9.1≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-89238 [CRITICAL] CWE-345 CVE-2026-89238: WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
nvd
CVE-2026-87830P3CRITICALCVSS 9.1≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-87830 [CRITICAL] CWE-917 CVE-2026-87830: In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, w
nvd
CVE-2026-92121P3HIGHCVSS 7.5≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-92121 [HIGH] CWE-693 CVE-2026-92121: In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring t
nvd
CVE-2026-95616P3HIGHCVSS 7.5≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-95616 [HIGH] CWE-190 CVE-2026-95616: An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An una
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so a
nvd
CVE-2026-85532P3HIGHCVSS 7.5≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-85532 [HIGH] CWE-20 CVE-2026-85532: Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. T
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes.
User
nvd
CVE-2026-92899P4MEDIUMCVSS 4.8≥ 4.0.0, < 4.0.2≥ 3.0.0, < 3.0.6+1 more2026-09-30
CVE-2026-92899 [MEDIUM] CWE-290 CVE-2026-92899: Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reu
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the
nvd