Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache wss4j |
|
| CPEs | cpe:2.3:a:apache:wss4j:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache wss4j |
Wed, 30 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-680 |
Wed, 30 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Wed, 30 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-680 |
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Wed, 30 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | |
| Title | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-30T13:17:31.672Z
Reserved: 2026-09-22T10:04:52.017Z
Link: CVE-2026-95616
Updated: 2026-09-30T13:17:31.672Z
Status : Analyzed
Published: 2026-09-30T13:17:28.863
Modified: 2026-10-06T17:21:33.233
Link: CVE-2026-95616
No data.
OpenCVE Enrichment
Updated: 2026-09-30T23:30:07Z
-
CWE-190
Integer Overflow or Wraparound