CVE-2026-92899: UsernameToken nonce replay bypass in Apache WSS4J · ZeroHour
04:18 UTC· just now
CVE-2026-92899
—
UsernameToken nonce replay bypass in Apache WSS4J
CVSS 3.1
4.8medium
EPSS
—
Published
()
Modified
AI analysis
Apache WSS4J stored each accepted UsernameToken Nonce as raw base64 text, while authentication compared the decoded bytes. Because the same bytes can be written as base64 in more than one way, an attacker who captured a valid digest UsernameToken could add a space to the Nonce so the password digest still verified but the replay cache did not recognize the nonce. A UsernameToken does not cover the message body, so the captured token could then be replayed on requests the attacker chose until it expired. This applies only where a nonce replay cache is configured—Apache CXF enables one by default—and only to password-digest tokens. It is not listed in CISA KEV and no public proof-of-concept is known.
What to do: Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4. Prioritize services that accept WS-Security UsernameTokens with a password digest and a nonce replay cache (the default in Apache CXF), and treat captured digest tokens as reusable until they expire.
Affected
Apache Software Foundation WSS4J
fixed in 2.4.4, 3.0.6, and 4.0.2 (earlier releases in those lines are affected)
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Apache WSS4J stores UsernameToken nonces as raw base64, so re-encoded nonces bypass replay protection; versions before 2.4.4, 3.0.6, and 4.0.2 affected.
CVE-2026-92899 (moderate) affects Apache WSS4J 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and all versions before 2.4.4. WSS4J caches UsernameToken nonces as raw base64 text while authentication uses the decoded bytes; because identical bytes have multiple valid base64 encodings, an attacker who captures a token can re-encode the nonce and bypass replay protection. Fixed releases are 2.4.4, 3.0.6, and 4.0.2.