---
id: CVE-2026-92121
title: >-
  In the WSS4J streaming (StAX) code, a signature reference using the
  WS-Security STR-Transform leaves an internal "inside signed content" flag
  permanently set
summary: >-
  In the WSS4J streaming (StAX) code, a signature reference using the
  WS-Security STR-Transform leaves an internal "inside signed content" flag
  permanently set. The WS-SecurityPolicy enforcer uses that flag to decide
  whether an element nee…
severity: none
vendor: Apache Software Foundation
product: 'org.apache.wss4j:wss4j-ws-security-stax'
affected:
  - 'org.apache.wss4j:wss4j-ws-security-stax >= 4.0.0 < 4.0.2'
  - 'org.apache.wss4j:wss4j-ws-security-stax >= 3.0.0 < 3.0.6'
  - 'org.apache.wss4j:wss4j-ws-security-stax < 2.4.4'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T13:17:21.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92121'
references:
  - url: 'https://lists.apache.org/thread.html/oop9p4hpl5o9byosb1qg3z7q1sgnn4pc'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/30/12'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T13:03:52.019Z'
---

## Overview

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. 
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
