Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Wed, 30 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-680 |
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-190 | |
| Metrics |
cvssV3_1
|
Wed, 30 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | |
| Title | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-30T13:17:31.672Z
Reserved: 2026-09-22T10:04:52.017Z
Link: CVE-2026-95616
Updated: 2026-09-30T13:17:31.672Z
Status : Received
Published: 2026-09-30T13:17:28.863
Modified: 2026-09-30T14:18:04.733
Link: CVE-2026-95616
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:30:17Z