This is an automated email from the ASF dual-hosted git repository.

coheigea pushed a commit to branch 2_4_x-fixes
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git


The following commit(s) were added to refs/heads/2_4_x-fixes by this push:
     new a33a198f0 Enforce isAllowRSA15KeyTransportAlgorithm for the StAX layer 
(#674)
a33a198f0 is described below

commit a33a198f01a95fc2e3a2d98a57341714170fc551
Author: Colm O hEigeartaigh <[email protected]>
AuthorDate: Mon Sep 7 11:06:46 2026 +0100

    Enforce isAllowRSA15KeyTransportAlgorithm for the StAX layer (#674)
---
 .../impl/processor/input/WSSEncryptedKeyInputHandler.java  | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git 
a/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
 
b/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
index 31b617ea9..9716181a0 100644
--- 
a/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
+++ 
b/ws-security-stax/src/main/java/org/apache/wss4j/stax/impl/processor/input/WSSEncryptedKeyInputHandler.java
@@ -63,6 +63,20 @@ public class WSSEncryptedKeyInputHandler extends 
XMLEncryptedKeyInputHandler {
             }
         }
 
+        // Reject RSA v1.5 key transport before key resolution or unwrap.
+        if (encryptionMethodType != null
+            && 
WSSConstants.NS_XENC_RSA15.equals(encryptionMethodType.getAlgorithm())
+            && !((WSSSecurityProperties) 
securityProperties).isAllowRSA15KeyTransportAlgorithm()) {
+            final WSInboundSecurityContext wsInboundSecurityContext =
+                (WSInboundSecurityContext) 
inputProcessorChain.getSecurityContext();
+            Boolean allowRSA15 =
+                
wsInboundSecurityContext.get(WSSConstants.PROP_ALLOW_RSA15_KEYTRANSPORT_ALGORITHM);
+            if (allowRSA15 == null || !allowRSA15) {
+                throw new 
WSSecurityException(WSSecurityException.ErrorCode.FAILED_CHECK,
+                                              
WSSConstants.PROP_ALLOW_RSA15_KEYTRANSPORT_ALGORITHM);
+            }
+        }
+
         super.handle(inputProcessorChain, encryptedKeyType, 
responsibleXMLSecStartXMLEvent, securityProperties);
     }
 

Reply via email to