org.apache.wss4j:wss4j-ws-security-common vulnerabilities
CVEs whose affected-version data names the org.apache.wss4j:wss4j-ws-security-common package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-95616High· 7.5An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7…
▾ TwilightApache Software Foundation · org.apache.wss4j:wss4j-ws-security-commonvia NVD
CVE-2026-85532NoneApache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds
Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fi…
▾ SunlitApache Software Foundation · org.apache.wss4j:wss4j-ws-security-commonvia NVD