Vulnerability in Apache WSS4J Allows Attacker-Controlled Key Management
CVE-2026-85532

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-85532?

The vulnerability in Apache WSS4J allows for the accepting of attacker-controlled derived-key lengths and offsets, potentially leading to cryptographic weaknesses and excessive resource consumption during the processing of specially crafted WS-Security messages. To address this issue, it is crucial for users to upgrade to the fixed versions 4.0.2, 3.0.6, or 2.4.4 which enforce stringent key length requirements and offset limits, enhancing overall security.

Affected Version(s)

Apache WSS4J 4.0.0 < 4.0.2

Apache WSS4J 3.0.0 < 3.0.6

Apache WSS4J 0 < 2.4.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was independently reported by Ho1aAs (GitHub: @HolaAsuka) and also found using Claude agents to study the security of open-source projects
.