Vulnerability in Apache WSS4J Allows Attacker-Controlled Key Management
CVE-2026-85532
Currently unrated
What is CVE-2026-85532?
The vulnerability in Apache WSS4J allows for the accepting of attacker-controlled derived-key lengths and offsets, potentially leading to cryptographic weaknesses and excessive resource consumption during the processing of specially crafted WS-Security messages. To address this issue, it is crucial for users to upgrade to the fixed versions 4.0.2, 3.0.6, or 2.4.4 which enforce stringent key length requirements and offset limits, enhancing overall security.
Affected Version(s)
Apache WSS4J 4.0.0 < 4.0.2
Apache WSS4J 3.0.0 < 3.0.6
Apache WSS4J 0 < 2.4.4