CVE-2026-95616: Vulnerability in Apache Software Foundation Apache WSS4J
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
AI Analysis
Technical Summary
CVE-2026-95616 describes an integer overflow in the DER bounds check of Apache WSS4J. The vulnerability occurs when WSS4J processes a SOAP message containing an X.509 certificate whose SubjectKeyIdentifier extension declares an excessively large length (0x7FFFFFFF). This causes WSS4J to allocate approximately 2 GB of memory for an eleven-byte extension before authenticating the message, enabling an unauthenticated attacker to exhaust server memory by sending repeated requests. The issue is resolved in Apache WSS4J versions 4.0.2, 3.0.6, and 2.4.4.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to cause a denial of service by exhausting server memory resources. The attack involves sending crafted SOAP messages that trigger large memory allocations during signature key reference resolution, potentially leading to service disruption.
Mitigation Recommendations
Users should upgrade Apache WSS4J to versions 4.0.2, 3.0.6, or 2.4.4, which contain fixes for this vulnerability. No other mitigation is indicated or required as the issue is resolved in these official releases.
CVE-2026-95616: Vulnerability in Apache Software Foundation Apache WSS4J
Description
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
CVSS v3.1
Score 7.5high
Affected software
Apache Software Foundation
Apache WSS4J
pkg:maven/Apache Software Foundation/org.apache.wss4j:wss4j-ws-security-commonRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-95616 describes an integer overflow in the DER bounds check of Apache WSS4J. The vulnerability occurs when WSS4J processes a SOAP message containing an X.509 certificate whose SubjectKeyIdentifier extension declares an excessively large length (0x7FFFFFFF). This causes WSS4J to allocate approximately 2 GB of memory for an eleven-byte extension before authenticating the message, enabling an unauthenticated attacker to exhaust server memory by sending repeated requests. The issue is resolved in Apache WSS4J versions 4.0.2, 3.0.6, and 2.4.4.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to cause a denial of service by exhausting server memory resources. The attack involves sending crafted SOAP messages that trigger large memory allocations during signature key reference resolution, potentially leading to service disruption.
Mitigation Recommendations
Users should upgrade Apache WSS4J to versions 4.0.2, 3.0.6, or 2.4.4, which contain fixes for this vulnerability. No other mitigation is indicated or required as the issue is resolved in these official releases.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-22T10:04:52.017Z
- State
- PUBLISHED
Threat ID: 6abd07622a4e24523d03fb2d
Added to database: 09/30/2026, 12:58:10 UTC
Last enriched: 09/30/2026, 13:03:06 UTC
Last updated: 09/30/2026, 13:34:13 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.