Posted by Colm O hEigeartaigh on Sep 30 Severity: important Affected versions: - Apache WSS4J 4.0.0 before 4.0.2 - Apache WSS4J 3.0.0 before 3.0.6 - Apache WSS4J before 2.4.4 Description: An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the...
CVE-2026-95616: Apache WSS4J: Unauthenticated denial of service via integer overflow in DER parsing of X.509 certificate extensions
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/1027
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.





