VulnSea

org.apache.wss4j:wss4j-ws-security-dom vulnerabilities

CVEs whose affected-version data names the org.apache.wss4j:wss4j-ws-security-dom package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-89238None
today

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions …

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions …

▾ SunlitApache Software Foundation · org.apache.wss4j:wss4j-ws-security-domvia NVD
CVE-2026-92899Medium· 4.8
today

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as bas…

▾ SunlitApache Software Foundation · org.apache.wss4j:wss4j-ws-security-domvia NVD
CVE-2026-88920None
today

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled ke…

An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled ke…

▾ SunlitApache Software Foundation · org.apache.wss4j:wss4j-ws-security-domvia NVD
org.apache.wss4j:wss4j-ws-security-dom vulnerabilities (CVEs) · VulnSea