Apache discloses seven WSS4J vulnerabilities — three rated important — all fixed in 2.4.4, 3.0.6, and 4.0.2
Seven same-day Apache WSS4J advisories (2026-09-30) cover a SAML Sender-Vouches authentication bypass, EncryptedHeader confusion, an unauthenticated DER-parsing DoS, skipped signature and element-protection checks, a UsernameToken nonce replay bypass, and…
On 2026-09-30, Apache published seven advisories for the WSS4J WS-Security library, all sharing the same affected ranges (4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and all versions before 2.4.4) and the same fixed versions (2.4.4, 3.0.6, and 4.0.2). Three flaws are rated important. CVE-2026-88920, in the DOM security processor, lets unauthenticated remote attackers forge authenticated SOAP messages via a crafted unsigned SAML Sender-Vouches flow. CVE-2026-89238, also in the DOM implementation, is an EncryptedHeader child-confusion flaw that can promote an attacker-controlled plaintext element as the decrypted header, producing incorrect confidentiality coverage and the wrong protected-header selection. CVE-2026-95616 is an unauthenticated denial-of-service via an integer overflow in the DER bounds check: a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF triggers excessive allocation during decoding. Three flaws are rated moderate: CVE-2026-85532 in ws-security-common accepts unbounded attacker-controlled derived-key lengths and offsets, risking cryptographically weak keys or excessive CPU use; CVE-2026-92121 in the streaming (StAX) security processor lets a WS-Security signature reference using the STR-Transform leave an internal 'inside signed content' flag permanently set, so later WS-SecurityPolicy signature checks can be skipped; and CVE-2026-92899 caches UsernameToken nonces as raw base64 text while authentication uses the decoded bytes, so an attacker who captures a token can re-encode the nonce and bypass replay protection. One flaw is rated low: CVE-2026-87830 in the StAX WS-SecurityPolicy validator, where certain relative or unsupported XPath expressions are converted into paths that never match, allowing element-protection checks to be skipped. None of the advisories report exploitation in the wild, and the reports are consistent on versions, fixes, and severities with no disagreements.
- Seven Apache WSS4J CVEs disclosed on 2026-09-30 via oss-security posts between 11:02 and 11:15 UTC.
- Identical affected ranges across all seven advisories: 4.0.0 before 4.0.2, 3.0.0 before 3.0.6, and all versions before 2.4.4; fixed releases are 2.4.4, 3.0.6, and 4.0.2.
- CVE-2026-88920 (important, wss4j-ws-security-dom): unauthenticated remote attackers can forge authenticated SOAP messages via a crafted unsigned SAML Sender-Vouches flow.
Coverage timelineoldest first · each row is one article
- · 10d agoCVE-2026-85532: Apache WSS4J: Insufficient Validation of Derived-Key Parameters
oss-security· 36
Apache WSS4J accepted unbounded derived-key lengths and offsets, risking weak keys or heavy CPU use.
- · 10d agoCVE-2026-87830: Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
oss-security· 24
Apache WSS4J streaming policy validation can skip element-protection checks for some XPath expressions.
- · 10d ago
Vulnerabilities in this storyAll →
- CVE-2026-889209.8—SAML Sender-Vouches Authentication Bypass in Apache WSS4Jpublished · Apache WSS4J+6 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-88920 |