CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference
Apache WSS4J streaming code can skip signature checks after an STR-Transform reference (CVE-2026-92121).
Apache disclosed CVE-2026-92121, a moderate flaw in the WSS4J streaming (StAX) security processor. A WS-Security signature reference that uses the STR-Transform leaves an internal "inside signed content" flag permanently set, so later WS-SecurityPolicy signature checks can be skipped. Affected releases are wss4j-ws-security-stax before 2.4.4, 3.0.0 before 3.0.6, and 4.0.0 before 4.0.2. The oss-security post does not report exploitation in the wild.
- Moderate flaw in WSS4J StAX streaming signature handling.
- An STR-Transform reference leaves an internal signed-content flag set.
- WS-SecurityPolicy signature checks can then be skipped.
- Fixed in 2.4.4, 3.0.6, and 4.0.2; no exploitation reported.
Vulnerabilities mentionedAll →
- CVE-2026-921217.5—WS-SecurityPolicy bypass in Apache WSS4J streaming codepublished · Apache WSS4J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92121 | WS-SecurityPolicy bypass in Apache WSS4J streaming code In Apache WSS4J’s streaming (StAX) code, a signature reference that uses the WS-Security STR-Transform leaves an internal “inside signed content” flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element still needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy that requires the SOAP Body to be signed can then be treated as satisfied even when the Body carries no signature, removing protection against XML Signature Wrapping; verification of signatures that are present is unaffected, and the DOM implementation is not affected. Applications that enforce WS-SecurityPolicy through WSS4J’s streaming path are affected and should move to 4.0.2, 3.0.6, or 2.4.4. No public proof of concept is known, the issue is not in CISA KEV, and CVSS has not yet been scored. |
Posted by Colm O hEigeartaigh on Sep 30 Severity: moderate Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) before 2.4.4 Description: In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set....
This source does not provide full text. Read it at seclists.org.