---
id: CVE-2026-92899
title: >-
  Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a
  captured token cannot be reused
summary: >-
  Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a
  captured token cannot be reused. It stored the Nonce as raw base64 text, but
  authentication decodes that text and uses the bytes.The same bytes can be
  written as bas…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-290
vendor: Apache Software Foundation
product: 'org.apache.wss4j:wss4j-ws-security-dom'
affected:
  - 'org.apache.wss4j:wss4j-ws-security-dom >= 4.0.0 < 4.0.2'
  - 'org.apache.wss4j:wss4j-ws-security-dom >= 3.0.0 < 3.0.6'
  - 'org.apache.wss4j:wss4j-ws-security-dom < 2.4.4'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T13:17:21.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92899'
references:
  - url: 'https://lists.apache.org/thread.html/nrzngsz1xm2lztq3t873663xx9wnrwm7'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/30/13'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-30T12:49:54.166060Z'
ingestedAt: '2026-09-30T13:03:51.966Z'
---

## Overview

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
