Apache Software FoundationCVE-2026-87830
Apache WSS4J: expression injection
Critical9.1CVE-2026-87830 · Published Sep 30, 2026
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache WSS4J Product | >= 4.0.0, < 4.0.2 | 4.0.2 |
| >= 3.0.0, < 3.0.6 | 3.0.6 | |
| < 2.4.4 | 2.4.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-917
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Apache WSS4J: integer overflow | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: insufficient authenticity check | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: protection mechanism failure | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass by spoofing | Medium4.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass | Critical9.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: resource exhaustion | High7.5 | 4.0.2+2 more |