Header Confusion Vulnerability in WSS4J by Apache
CVE-2026-89238

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-89238?

A vulnerability in WSS4J allows an attacker to exploit a child confusion scenario within the EncryptedHeader element. This flaw could lead to the disclosure of sensitive information as an attacker might manipulate a plaintext element to be perceived as the decrypted header. Such misinterpretation could result in reduced confidentiality measures and potential policy bypass. Users are advised to update to the latest versions (4.0.2, 3.0.6, or 2.4.4) to mitigate this risk.

Affected Version(s)

Apache WSS4J 4.0.0 < 4.0.2

Apache WSS4J 3.0.0 < 3.0.6

Apache WSS4J 0 < 2.4.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported by n0mi1k
.