Header Confusion Vulnerability in WSS4J by Apache
CVE-2026-89238
Currently unrated
What is CVE-2026-89238?
A vulnerability in WSS4J allows an attacker to exploit a child confusion scenario within the EncryptedHeader element. This flaw could lead to the disclosure of sensitive information as an attacker might manipulate a plaintext element to be perceived as the decrypted header. Such misinterpretation could result in reduced confidentiality measures and potential policy bypass. Users are advised to update to the latest versions (4.0.2, 3.0.6, or 2.4.4) to mitigate this risk.
Affected Version(s)
Apache WSS4J 4.0.0 < 4.0.2
Apache WSS4J 3.0.0 < 3.0.6
Apache WSS4J 0 < 2.4.4