7.5

CVE-2026-92121

Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an STR-Transform reference

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. 
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Wss4j Version < 2.4.4
Apache ≫ Wss4j Version >= 3.0.0 < 3.0.6
Apache ≫ Wss4j Version >= 4.0.0 < 4.0.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.262
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

https://lists.apache.org/thread.html/oop9p4hpl5o9byosb1qg3z7q1sgnn4pc
Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/09/30/12
Third Party Advisory
Mailing List