CVE-2026-85532 PUBLISHED

Apache WSS4J: Insufficient Validation of Derived-Key Parameters

Assigner: apache
Reserved: 04.09.2026 Published: 30.09.2026 Updated: 30.09.2026

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache WSS4J
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.2 (excl.)
  • affected from 3.0.0 to 3.0.6 (excl.)
  • affected from 0 to 2.4.4 (excl.)

Credits

  • This issue was independently reported by Ho1aAs (GitHub: @HolaAsuka) and also found using Claude agents to study the security of open-source projects finder

References

Problem Types

  • CWE-20 Improper input validation CWE