Apache WSS4J

7 known vulnerabilities in Apache WSS4J, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-95616 CVSS 7.5 high An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP…
  • CVE-2026-92899 CVSS 4.8 medium Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64…
  • CVE-2026-92121 CVSS 7.5 high In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content"…
  • CVE-2026-89238 CVSS 9.1 critical WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect…
  • CVE-2026-88920 CVSS 9.8 critical An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP…
  • CVE-2026-87830 CVSS 9.1 critical In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that…
  • CVE-2026-85532 CVSS 7.5 high Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically…