Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-95616— Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions

Quick assessment

Affected
Apache Software Foundation Apache WSS4J
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WSS4J 中 DER 边界检查存在整数溢出漏洞,导致超大内存分配能够通过验证。未经身份验证的攻击者可以发送一个包含 X.509 证书的 SOAP 消息,该证书的 SubjectKeyIdentifier 扩展字段声明的长度为 0x7FFFFFFF。WSS4J 在解析签名密钥引用时会对该字段进行解码,且此过程发生在消息认证之前,因此一个仅 11 字节的扩展字段即可触发约 2 GB 的内存分配。通过重复发送此类请求,攻击者可耗尽服务器内存资源。 建议用户升级至 4.0.2、3.0.6 或 2.4.4 版本,这些版本已

AI Predicted 7.5 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-95616

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
Source: CVE Program / CVE List V5
Vulnerability Description
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache WSS4J 4.0.0 ~ 4.0.2 -

II. Public POCs for CVE-2026-95616

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-95616

请登录查看更多情报信息。

Other References for CVE-2026-95616 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-30 · 19 CVEs total

CVE-2026-102508 9.2 CRITICAL Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, an
CVE-2026-94052 9.1 CRITICAL Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-77185 9.1 CRITICAL Apache MINA SSHD: Asynchronous authentication can bypass signature verification
CVE-2026-94053 9.1 CRITICAL Apache MINA SSHD: LDAP injection in sshd-ldap
CVE-2026-102509 8.7 HIGH Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver an
CVE-2026-102510 8.7 HIGH Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled len
CVE-2026-102511 8.5 HIGH Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed resp
CVE-2026-93994 8.1 HIGH Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-94002 7.5 HIGH Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
CVE-2026-93995 6.5 MEDIUM Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the ser
CVE-2026-94029 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-handle extension
CVE-2026-93996 6.5 MEDIUM Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
CVE-2026-92899 Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce
CVE-2026-85532 Apache WSS4J: Insufficient Validation of Derived-Key Parameters
CVE-2026-87830 Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protection checks.
CVE-2026-88920 Apache WSS4J: SAML Sender-Vouches Authentication Bypass
CVE-2026-89238 Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-header selecti
CVE-2026-92121 Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming code after an ST

IV. Related Vulnerabilities

V. Comments for CVE-2026-95616

No comments yet


Leave a comment