Severity: moderate 

Affected versions:

- Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 4.0.0 before 4.0.2
- Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) 3.0.0 before 3.0.6
- Apache WSS4J (org.apache.wss4j:wss4j-ws-security-stax) before 2.4.4

Description:

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security 
STR-Transform leaves an internal "inside signed content" flag permanently set. 
The WS-SecurityPolicy enforcer uses that flag to decide whether an element 
needs checking, so it stops evaluating SignedParts and SignedElements for the 
rest of the message. A policy requiring the SOAP Body to be signed is then 
satisfied even when the Body carries no signature, removing the protection 
against XML Signature Wrapping. Signature verification itself is unaffected. 
The DOM code is not affected. 
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix 
this issue.

Credit:

Reported by n0mi1k (finder)

References:

https://ws.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-92121


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to