Skip to content

Apache WSS4J: integer overflow

High7.5CVE-2026-95616 · Published Sep 30, 2026

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected versions

PackageAffectedFixed in
Apache WSS4J
Product
>= 4.0.0, < 4.0.24.0.2
>= 3.0.0, < 3.0.63.0.6
< 2.4.42.4.4
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache WSS4J: insufficient authenticity check
Critical9.1Sep 30
Apache WSS4J: protection mechanism failure
High7.5Sep 30
Apache WSS4J: authentication bypass by spoofing
Medium4.8Sep 30
Apache WSS4J: expression injection
Critical9.1Sep 30
Apache WSS4J: authentication bypass
Critical9.8Sep 30
Apache WSS4J: resource exhaustion
High7.5Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.