CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions

Published Sep 30, 2026
·
Updated

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected Software

1 affected component
Apache WSS4J>=4.0.0<=4.0.1, >=3.0.0<=3.0.5, >=2.4.0<=2.4.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache WSS4J to a version that resolves this vulnerability.

    Fixed in 4.0.2
  2. Upgrade

    Upgrade Apache WSS4J to a version that resolves this vulnerability.

    Fixed in 3.0.6
  3. Upgrade

    Upgrade Apache WSS4J to a version that resolves this vulnerability.

    Fixed in 2.4.4

Event History

Sep 30, 2026
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated attacker who can send SOAP messages to an endpoint that uses WSS4J to resolve an X.509 certificate-based signature key reference can trigger the allocation. Repeated malicious requests can exhaust server memory.

2

Does exploitation require a valid certificate or successful message authentication?

No. The malformed SubjectKeyIdentifier extension is decoded while WSS4J resolves the signature key reference, before the SOAP message is authenticated.

3

What versions contain the fix?

Upgrade to Apache WSS4J 4.0.2, 3.0.6, or 2.4.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203