Skip to content
CVE-2026-89238: EncryptedHeader confusion in Apache WSS4J can bypass policy · ZeroHour