CVE-2026-85532: Apache WSS4J: Insufficient Validation of Derived-Key Parameters
Apache WSS4J accepted unbounded derived-key lengths and offsets, risking weak keys or heavy CPU use.
Apache disclosed moderate-severity CVE-2026-85532 in WSS4J's ws-security-common component. The library accepted attacker-controlled derived-key lengths and offsets without adequate bounds, which could permit cryptographically weak keys or excessive CPU use. Affected versions are 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and releases before 2.4.4. No in-the-wild exploitation is stated.
- Moderate flaw in Apache WSS4J derived-key parameter checks.
- Unbounded lengths and offsets can yield weak keys or heavy CPU use.
- Patched in 4.0.2, 3.0.6, and 2.4.4; exploitation not reported.
Vulnerabilities mentionedAll →
- CVE-2026-855327.5—Insufficient derived-key validation in Apache WSS4Jpublished · Apache WSS4J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85532 | Insufficient derived-key validation in Apache WSS4J Apache WSS4J did not adequately bound attacker-controlled derived-key lengths and offsets when processing WS-Security messages. A crafted message can force cryptographically weak keys or drive excessive CPU and memory use. The flaw is improper input validation (CWE-20) in the WSS4J library, which is commonly pulled in by Java SOAP stacks that handle WS-Security. Users of releases before the fixed versions 2.4.4, 3.0.6, and 4.0.2 are affected. There is no known public proof of concept, the issue is not on the CISA KEV list, and exploitation in the wild is not known. Do: Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4, matching the release line you already use. Identify every application that processes untrusted WS-Security messages (often via Apache CXF or similar SOAP stacks) and confirm the fixed library version is on the classpath. Until then, restrict or carefully gate WS-Security endpoints that accept derived-key material from untrusted clients. |
Posted by Colm O hEigeartaigh on Sep 30 Severity: moderate Affected versions: - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-common) 4.0.0 before 4.0.2 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-common) 3.0.0 before 3.0.6 - Apache WSS4J (org.apache.wss4j:wss4j-ws-security-common) before 2.4.4 Description: Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and...
This source does not provide full text. Read it at seclists.org.