CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
Apache WSS4J streaming code can skip signature checks after an STR-Transform reference (CVE-2026-92121).
Apache disclosed CVE-2026-92121, a moderate flaw in the WSS4J streaming (StAX) security processor. A WS-Security signature reference that uses the STR-Transform leaves an internal "inside signed content" flag permanently set, so later WS-SecurityPolicy signature checks can be skipped. Affected releases are wss4j-ws-security-stax before 2.4.4, 3.0.0 before 3.0.6, and 4.0.0 before 4.0.2. The oss-security post does not report exploitation in the wild.
48