Integer Overflow Vulnerability in WSS4J Affects Apache Software Foundation
CVE-2026-95616
7.5HIGH
What is CVE-2026-95616?
An integer overflow vulnerability in WSS4J enables attackers to bypass a DER bounds check, allowing oversized allocations to go undetected. By sending a specially crafted SOAP message containing an X.509 certificate with a SubjectKeyIdentifier extension length set to 0x7FFFFFFF, an unauthenticated attacker can force the server to allocate excessive memory. This exploitation results in server memory exhaustion due to substantial allocation requests. Users are advised to upgrade to WSS4J versions 4.0.2, 3.0.6, or 2.4.4 to mitigate this risk.
Affected Version(s)
Apache WSS4J 4.0.0 < 4.0.2
Apache WSS4J 3.0.0 < 3.0.6
Apache WSS4J 0 < 2.4.4