CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce

Published Sep 30, 2026
·
Updated

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected Software

1 affected component
Apache WSS4J<4.0.2, <3.0.6, <2.4.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache WSS4J to a version that resolves this vulnerability.

    Fixed in 4.0.2
  2. Upgrade

    Upgrade Apache WSS4J to a version that resolves this vulnerability.

    Fixed in 3.0.6
  3. Upgrade

    Upgrade Apache WSS4J to a version that resolves this vulnerability.

    Fixed in 2.4.4

Event History

Sep 30, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this replay bypass?

Deployments are affected when they use a nonce replay cache and accept UsernameTokens authenticated with a password digest. Apache CXF has a nonce replay cache configured by default.

2

What does an attacker need to exploit the issue?

An attacker needs to capture an authenticated request containing a password-digest UsernameToken. They can add a space to the base64-encoded Nonce and replay the token while it remains valid.

3

What can an attacker do with a replayed token?

Because the UsernameToken does not cover the message body, the captured token can be reused in requests chosen by the attacker until the token expires.

4

How can this be remediated?

Upgrade Apache WSS4J to version 4.0.2, 3.0.6, or 2.4.4. These versions key the replay cache using the decoded Nonce rather than its raw base64 representation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203