CVE-2026-92899: Vulnerability in Apache Software Foundation Apache WSS4J
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
AI Analysis
Technical Summary
Apache WSS4J stores the Nonce of each accepted UsernameToken as raw base64 text to prevent replay attacks. However, because the authentication process decodes the base64 text and uses the underlying bytes, an attacker can resend a captured authenticated request with a modified base64 Nonce (e.g., adding a space) that still decodes to the same bytes. This causes the replay cache to fail to recognize the token as a replay, allowing reuse of the token until it expires. This vulnerability affects deployments with a nonce replay cache configured (such as Apache CXF by default) and only impacts tokens using password digest authentication. The fix involves keying the replay cache on the decoded Nonce bytes rather than the raw base64 text.
Potential Impact
An attacker who captures an authenticated request can replay it by modifying the base64 encoding of the Nonce without invalidating the password digest verification. This allows reuse of the UsernameToken on requests of the attacker's choosing until the token expires, potentially bypassing replay protections. The vulnerability affects systems using nonce replay caches and password digest tokens, potentially undermining authentication integrity.
Mitigation Recommendations
Users should upgrade Apache WSS4J to versions 4.0.2, 3.0.6, or 2.4.4 where the replay cache keys on the decoded Nonce bytes, preventing this replay attack. No other mitigation is indicated or required once these versions are deployed.
CVE-2026-92899: Vulnerability in Apache Software Foundation Apache WSS4J
Description
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
CVSS v3.1
Score 4.8medium
Affected software
Apache Software Foundation
Apache WSS4J
pkg:maven/Apache Software Foundation/org.apache.wss4j:wss4j-ws-security-domRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache WSS4J stores the Nonce of each accepted UsernameToken as raw base64 text to prevent replay attacks. However, because the authentication process decodes the base64 text and uses the underlying bytes, an attacker can resend a captured authenticated request with a modified base64 Nonce (e.g., adding a space) that still decodes to the same bytes. This causes the replay cache to fail to recognize the token as a replay, allowing reuse of the token until it expires. This vulnerability affects deployments with a nonce replay cache configured (such as Apache CXF by default) and only impacts tokens using password digest authentication. The fix involves keying the replay cache on the decoded Nonce bytes rather than the raw base64 text.
Potential Impact
An attacker who captures an authenticated request can replay it by modifying the base64 encoding of the Nonce without invalidating the password digest verification. This allows reuse of the UsernameToken on requests of the attacker's choosing until the token expires, potentially bypassing replay protections. The vulnerability affects systems using nonce replay caches and password digest tokens, potentially undermining authentication integrity.
Mitigation Recommendations
Users should upgrade Apache WSS4J to versions 4.0.2, 3.0.6, or 2.4.4 where the replay cache keys on the decoded Nonce bytes, preventing this replay attack. No other mitigation is indicated or required once these versions are deployed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-17T10:21:29.052Z
- State
- PUBLISHED
Threat ID: 6abd07622a4e24523d03fb2c
Added to database: 09/30/2026, 12:58:10 UTC
Last enriched: 09/30/2026, 13:03:12 UTC
Last updated: 09/30/2026, 13:03:55 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.