CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
Apache WSS4J stores UsernameToken nonces as raw base64, so re-encoded nonces bypass replay protection; versions before 2.4.4, 3.0.6, and 4.0.2 affected.
CVE-2026-92899 (moderate) affects Apache WSS4J 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and all versions before 2.4.4. WSS4J caches UsernameToken nonces as raw base64 text while authentication uses the decoded bytes; because identical bytes have multiple valid base64 encodings, an attacker who captures a token can re-encode the nonce and bypass replay protection. Fixed releases are 2.4.4, 3.0.6, and 4.0.2.
- WSS4J stores nonces as raw base64 text but authenticates using decoded bytes
- Re-encoding the nonce lets a captured UsernameToken bypass replay protection
- Affected: 4.0.0<4.0.2, 3.0.0<3.0.6, and <2.4.4; severity rated moderate
Vulnerabilities mentionedAll →
- CVE-2026-928994.8—UsernameToken nonce replay bypass in Apache WSS4Jpublished · Apache Software Foundation WSS4J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92899 | UsernameToken nonce replay bypass in Apache WSS4J Apache WSS4J stored each accepted UsernameToken Nonce as raw base64 text, while authentication compared the decoded bytes. Because the same bytes can be written as base64 in more than one way, an attacker who captured a valid digest UsernameToken could add a space to the Nonce so the password digest still verified but the replay cache did not recognize the nonce. A UsernameToken does not cover the message body, so the captured token could then be replayed on requests the attacker chose until it expired. This applies only where a nonce replay cache is configured—Apache CXF enables one by default—and only to password-digest tokens. It is not listed in CISA KEV and no public proof-of-concept is known. Upgrade Apache WSS4J to 4.0.2, 3.0.6, or 2.4.4. Prioritize services that accept WS-Security UsernameTokens with a password digest and a nonce replay cache (the default in Apache CXF), and treat captured digest tokens as reusable until they expire. |
Posted by Colm O hEigeartaigh on Sep 30 Severity: moderate Affected versions: - Apache WSS4J 4.0.0 before 4.0.2 - Apache WSS4J 3.0.0 before 3.0.6 - Apache WSS4J before 2.4.4 Description: Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an...
This source does not provide full text. Read it at seclists.org.