CVE-2026-87830: Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
Apache WSS4J streaming policy validation can skip element-protection checks for some XPath expressions.
Apache disclosed low-severity CVE-2026-87830 in the StAX streaming WS-SecurityPolicy validator of WSS4J. Certain relative or unsupported XPath expressions can be converted into paths that never match, so element-protection checks may be skipped. Affected wss4j-ws-security-policy-stax ranges are 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and releases before 2.4.4. The advisory does not report exploitation.
- Low-severity flaw in the StAX WS-SecurityPolicy validator.
- Some XPath expressions become paths that never match protected elements.
- Fixed in 4.0.2, 3.0.6, and 2.4.4; no exploitation reported.
Vulnerabilities mentionedAll →
- CVE-2026-878309.1—WS-SecurityPolicy check bypass in Apache WSS4J streaming validatorpublished · Apache Software Foundation Apache WSS4J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87830 | WS-SecurityPolicy check bypass in Apache WSS4J streaming validator Apache WSS4J's StAX streaming WS-SecurityPolicy validator can turn certain relative or unsupported XPath expressions into paths that never match the actual XML element path. A remote SOAP peer can then send a required element without the signature or encryption the policy expects, so element-protection checks are skipped. Services that rely on that streaming validator may accept SOAP messages that violate required protection. Users of Apache WSS4J on the affected release lines are advised to move to 4.0.2, 3.0.6, or 2.4.4. No public proof of concept is known, the issue is not in CISA KEV, and CVSS has not yet been scored. Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4 for the release line in use, including applications and frameworks that bundle the library. After upgrading, recheck SOAP services that use the StAX streaming WS-SecurityPolicy validator so required elements are still enforced as signed or encrypted. |
Posted by Colm O hEigeartaigh on Sep 30 Severity: low Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-policy-stax) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-policy-stax) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-policy-stax) before 2.4.4 Description: In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the...
This source does not provide full text. Read it at seclists.org.