{"id":"CVE-2026-95616","title":"An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation","summary":"An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-190"],"vendor":"Apache Software Foundation","product":"org.apache.wss4j:wss4j-ws-security-common","affected":["org.apache.wss4j:wss4j-ws-security-common >= 4.0.0 < 4.0.2","org.apache.wss4j:wss4j-ws-security-common >= 3.0.0 < 3.0.6","org.apache.wss4j:wss4j-ws-security-common < 2.4.4"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T14:18:04.733","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95616","references":[{"url":"https://lists.apache.org/thread.html/sdf0fsphkg4qbj7nh2brjgwvcmd67hct","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/30/14","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-30T12:43:35.342143Z"},"ingestedAt":"2026-09-30T13:03:51.968Z","slug":"CVE-2026-95616","body":"## Overview\n\nAn integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}