CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
Apache WSS4J disclosed CVE-2026-95616, an unauthenticated denial-of-service via integer overflow in X.509 DER parsing; fixed in 2.4.4, 3.0.6, and 4.0.2.
CVE-2026-95616 (rated important) is an integer overflow in Apache WSS4J's DER bounds check that lets oversized allocations pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF, triggering excessive allocation during decoding. Affected versions are WSS4J 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and all versions before 2.4.4.
- Unauthenticated DoS via integer overflow in DER bounds check
- Malicious SOAP message with oversized X.509 SubjectKeyIdentifier triggers allocation
- Fixed in versions 4.0.2, 3.0.6, and 2.4.4
Vulnerabilities mentionedAll →
- CVE-2026-956167.5—Unauthenticated memory DoS in Apache WSS4J DER parsingpublished · Apache WSS4J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-95616 | Unauthenticated memory DoS in Apache WSS4J DER parsing Apache WSS4J has an integer overflow in its DER bounds check that lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message whose X.509 certificate SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes that extension while resolving the signature key reference, before the message is authenticated, so a tiny extension can force about a 2 GB allocation. Repeating the request exhausts server memory and denies service, with no confidentiality or integrity impact. Any service that uses a vulnerable WSS4J release to process unauthenticated SOAP with WS-Security signatures is affected. There is no known public proof of concept and the issue is not listed in CISA KEV. Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4 (whichever release line you use) and redeploy every application that embeds it, including transitive dependencies pulled in by Apache CXF or other WS-Security stacks. Until the upgrade is in place, constrain process memory and request size for unauthenticated SOAP endpoints so a single oversized allocation cannot exhaust the host. |
Posted by Colm O hEigeartaigh on Sep 30 Severity: important Affected versions: - Apache WSS4J 4.0.0 before 4.0.2 - Apache WSS4J 3.0.0 before 3.0.6 - Apache WSS4J before 2.4.4 Description: An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the...
This source does not provide full text. Read it at seclists.org.