Severity: important 

Affected versions:

- Apache WSS4J 4.0.0 before 4.0.2
- Apache WSS4J 3.0.0 before 3.0.6
- Apache WSS4J before 2.4.4

Description:

An integer overflow in WSS4J's DER bounds check lets an oversized allocation 
pass validation. An unauthenticated attacker can send a SOAP message carrying 
an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 
0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, 
before the message is authenticated, so an eleven-byte extension triggers a 2 
GB allocation. Repeated requests exhaust server memory.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix 
this issue.

References:

https://ws.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-95616


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to