CVE-2026-92899: Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 4.0.2 - Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
Which deployments are exposed to this replay bypass?
Deployments are affected when they use a nonce replay cache and accept UsernameTokens authenticated with a password digest. Apache CXF has a nonce replay cache configured by default.
What does an attacker need to exploit the issue?
An attacker needs to capture an authenticated request containing a password-digest UsernameToken. They can add a space to the base64-encoded Nonce and replay the token while it remains valid.
What can an attacker do with a replayed token?
Because the UsernameToken does not cover the message body, the captured token can be reused in requests chosen by the attacker until the token expires.
How can this be remediated?
Upgrade Apache WSS4J to version 4.0.2, 3.0.6, or 2.4.4. These versions key the replay cache using the decoded Nonce rather than its raw base64 representation.