Integer Overflow Vulnerability in WSS4J Affects Apache Software Foundation
CVE-2026-95616

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 September 2026

What is CVE-2026-95616?

An integer overflow vulnerability in WSS4J enables attackers to bypass a DER bounds check, allowing oversized allocations to go undetected. By sending a specially crafted SOAP message containing an X.509 certificate with a SubjectKeyIdentifier extension length set to 0x7FFFFFFF, an unauthenticated attacker can force the server to allocate excessive memory. This exploitation results in server memory exhaustion due to substantial allocation requests. Users are advised to upgrade to WSS4J versions 4.0.2, 3.0.6, or 2.4.4 to mitigate this risk.

Affected Version(s)

Apache WSS4J 4.0.0 < 4.0.2

Apache WSS4J 3.0.0 < 3.0.6

Apache WSS4J 0 < 2.4.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.