CVE-2026-89238: Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selection
Apache WSS4J EncryptedHeader parsing can accept attacker plaintext as the protected header (CVE-2026-89238).
Apache disclosed CVE-2026-89238, rated important, in the DOM implementation of Apache WSS4J. EncryptedHeader child confusion can promote an attacker-controlled plaintext element as the decrypted header, producing incorrect confidentiality coverage and the wrong protected-header selection. Affected packages are wss4j-ws-security-dom before 2.4.4, 3.0.0 before 3.0.6, and 4.0.0 before 4.0.2. No in-the-wild exploitation is stated.