Apache Software FoundationCVE-2026-95616
Apache WSS4J: integer overflow
High7.5CVE-2026-95616 · Published Sep 30, 2026
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache WSS4J Product | >= 4.0.0, < 4.0.2 | 4.0.2 |
| >= 3.0.0, < 3.0.6 | 3.0.6 | |
| < 2.4.4 | 2.4.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-190
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Apache WSS4J: insufficient authenticity check | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: protection mechanism failure | High7.5 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass by spoofing | Medium4.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: expression injection | Critical9.1 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: authentication bypass | Critical9.8 | 4.0.2+2 more |
| Sep 30 | Apache WSS4J: resource exhaustion | High7.5 | 4.0.2+2 more |