Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <167cca1b-a8b3-2539-33f1-c3319d18f174@apache.org>
Date: Wed, 30 Sep 2026 10:36:24 +0000
From: Colm O hEigeartaigh <coheigea@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-92121: Apache WSS4J: WS-SecurityPolicy signature checks
 skipped in the streaming code after an STR-Transform reference 

Severity: moderate 

Affected versions:

- Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 4.0.0 before 4.0.2
- Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 3.0.0 before 3.0.6
- Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) before 2.4.4

Description:

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. 
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.

Credit:

Reported by n0mi1k (finder)

References:

https://ws.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-92121

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.