Back

HIGH

Apache WSS4J: Insufficient Validation of Derived-Key Parameters

Published Sep 30, 2026

Description

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 30, 2026
Updated Sep 30, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a