CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 4.0.2 - Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 3.0.6 - Upgrade
Upgrade
Apache WSS4Jto a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker who can send SOAP messages to an endpoint that uses WSS4J to resolve an X.509 certificate-based signature key reference can trigger the allocation. Repeated malicious requests can exhaust server memory.
Does exploitation require a valid certificate or successful message authentication?
No. The malformed SubjectKeyIdentifier extension is decoded while WSS4J resolves the signature key reference, before the SOAP message is authenticated.
What versions contain the fix?
Upgrade to Apache WSS4J 4.0.2, 3.0.6, or 2.4.4.