TL;DR
Developers disclosed six Apache WSS4J vulnerabilities. These critical security defects include authentication bypasses and denial of service flaws. Administrators must update their libraries to version 4.0.2, 3.0.6, or 2.4.4 immediately.
- Total: 6 CVEs
- Severity: 2 Critical · 3 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-88920
- Action: Apply the latest security updates now
Turn Apache CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-88920 | 9.8 | CWE-287 | 4.0.2, 3.0.6, 2.4.4 | Not exploited |
| CVE-2026-89238 | 9.1 | CWE-345 | 4.0.2, 3.0.6, 2.4.4 | Not exploited |
| CVE-2026-95616 | 7.5 | CWE-190 | 4.0.2, 3.0.6, 2.4.4 | Not exploited |
| CVE-2026-92121 | 7.5 | CWE-693 | 4.0.2, 3.0.6, 2.4.4 | Not exploited |
| CVE-2026-85532 | 7.5 | CWE-20 | 4.0.2, 3.0.6, 2.4.4 | Not exploited |
| CVE-2026-92899 | 4.8 | CWE-290 | 4.0.2, 3.0.6, 2.4.4 | Not exploited |
Why It Matters
Apache WSS4J provides WS-Security implementations for countless enterprise Java applications. Consequently, weaknesses in this library expose sensitive SOAP messaging infrastructure to severe risks. The most critical defect, CVE-2026-88920, carries a CVSS base score of 9.8. This flaw allows remote attackers to forge authenticated messages entirely. Currently, researchers have not confirmed any active exploitation of these Apache WSS4J vulnerabilities in the wild. Additionally, no public proof-of-concept exploit code currently exists. However, unpatched servers remain highly susceptible to message forgery and memory exhaustion.
How The Attack Works
The flaws target distinct XML parsing and cryptographic validation routines. CVE-2026-88920 involves an authentication bypass in the DOM security processor. An unauthenticated attacker supplies a crafted unsigned SAML sender-vouches assertion containing a malicious key. The processor validates the key improperly, accepting forged SOAP messages.
Meanwhile, CVE-2026-95616 exploits an integer overflow in the DER bounds checker. An attacker sends an X.509 certificate with a maximum-length SubjectKeyIdentifier extension. This triggers a massive two-gigabyte memory allocation, causing denial of service. Furthermore, CVE-2026-89238 allows attackers to promote plaintext elements as decrypted headers through child confusion. Additionally, CVE-2026-92121 removes protection against XML Signature Wrapping. A WS-SecurityPolicy enforcer stops evaluating signed elements prematurely due to an internal flag error. Other flaws enable nonce replay attacks and allow cryptographically weak keys.
Affected Versions
These Apache WSS4J vulnerabilities impact multiple release branches. The defects affect all library versions prior to 4.0.2, 3.0.6, and 2.4.4.
Patch Or Mitigation Steps
Development teams must update their project dependencies immediately. The Apache Software Foundation released versions 4.0.2, 3.0.6, and 2.4.4 to resolve all six flaws. You can obtain the patched libraries directly from the Apache WSS4J download page. Applying these updates ensures secure authentication and prevents memory exhaustion attacks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!