在 WSS4J 流式(StAX)代码中,使用 WS-Security STR-Transform 的签名引用会将内部“位于签名内容内”标志永久置位。WS-SecurityPolicy 执行器依赖该标志来决定是否需要检查某个元素,因此它会停止对消息剩余部分的 SignedParts 和 SignedElements 进行评估。这样一来,即使 SOAP Body 未包含任何签名,要求对 SOAP Body 进行签名的策略仍会被视为满足,从而削弱了对 XML 签名包装(XML Signature Wrapping)攻击的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache WSS4J | 4.0.0 ~ 4.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102508 | 9.2 CRITICAL | Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an |
| CVE-2026-94052 | 9.1 CRITICAL | Apache MINA SSHD: LDAP password authentication ineffective |
| CVE-2026-77185 | 9.1 CRITICAL | Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
| CVE-2026-94053 | 9.1 CRITICAL | Apache MINA SSHD: LDAP injection in sshd-ldap |
| CVE-2026-102509 | 8.7 HIGH | Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an |
| CVE-2026-102510 | 8.7 HIGH | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len |
| CVE-2026-102511 | 8.5 HIGH | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp |
| CVE-2026-93994 | 8.1 HIGH | Apache MINA SSHD: Repeated-publickey policy bypass on server |
| CVE-2026-94002 | 7.5 HIGH | Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies |
| CVE-2026-93995 | 6.5 MEDIUM | Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser |
| CVE-2026-94029 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension |
| CVE-2026-93996 | 6.5 MEDIUM | Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read |
| CVE-2026-95616 | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.5 | |
| CVE-2026-85532 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters | |
| CVE-2026-87830 | Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks. | |
| CVE-2026-88920 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass | |
| CVE-2026-89238 | Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti | |
| CVE-2026-92899 | Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce |
No comments yet